A reflected cross-site scripting (XSS) vulnerability has been identified in the authentication redirect flow of Siemens Teamcenter, allowing attackers to inject malicious JavaScript into the sessions of authenticated users. This exploitation could enable unauthorized actions or data access within the affected user's Teamcenter session. The vulnerability, tracked as CVE-2026-58113, affects several versions of Teamcenter, including V2412, V2506, V2512, and V2606, prior to specific patch levels. Siemens recommends users update to the latest versions to mitigate this risk. It's crucial for organizations using Teamcenter to act quickly to protect their systems from potential exploitation.
Articles tagged "XSS"
Found 27 articles
Rockwell Automation has identified serious vulnerabilities in its ArmorStart LT product, specifically versions up to v2.001. These vulnerabilities could allow attackers to execute malicious scripts through cross-site scripting (XSS) attacks or cause a denial of service by sending crafted HTTP requests, leading to web server outages. Users are strongly advised to update to firmware version v2.002 to mitigate these risks. The vulnerabilities affect critical manufacturing systems worldwide, raising concerns about the security of industrial control systems. Organizations should act swiftly to ensure their systems are protected, following best practices for cybersecurity.
A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.
Researchers at Pwn have identified a serious vulnerability in WordPress, dubbed the XSS2Shell flaw, which allows attackers to take control of an admin account and execute remote code. The issue arises when a user inputs a non-existent username, triggering a response from WordPress that contains a minor formatting error. This flaw can be exploited to gain unauthorized access to the server. WordPress users are strongly advised to update their installations to the patched versions to protect against this vulnerability. Failure to do so could leave sites open to full server takeover, posing significant risks to website security and data integrity.
WordPress has addressed a serious vulnerability in its login screen that affects all versions of the platform. This flaw, known as CVE-2026-64638 and rated with a CVSS score of 8.9, allows for pre-authentication reflected cross-site scripting (XSS). Researchers from pwn.ai have demonstrated that this vulnerability could potentially be exploited to execute PHP code on the server, particularly if an administrator interacts with a malicious page. As this issue impacts every WordPress installation, users and website administrators are strongly encouraged to apply the patch immediately to secure their sites and prevent potential exploitation.
Johnson Controls has identified multiple vulnerabilities in their OpenBlue Employee software, specifically versions up to V2025.3.1. These flaws could allow attackers to upload malicious files, execute cross-site scripting (XSS) attacks, or inject harmful HTML content, posing significant risks to users. The vulnerabilities are particularly concerning as they affect critical infrastructure sectors, including manufacturing, transportation, and energy. Johnson Controls advises users to apply the latest updates and implement strong access controls to mitigate potential risks. The company has outlined specific defensive measures to help secure the application and protect users from exploitation.
Zimbra has released an update to fix several serious security vulnerabilities, including a command injection flaw in its Simple Network Management Protocol (SNMP) component. The update, version 10.1.20, addresses a total of nine vulnerabilities, with the SNMP issue being particularly concerning as it could allow attackers to execute unauthorized commands when SNMP notifications are enabled. This could potentially expose sensitive data or disrupt services for organizations using Zimbra's platform. Companies that rely on Zimbra for email and collaboration tools need to update their systems promptly to mitigate these risks and ensure their environments remain secure.
Palo Alto Networks has issued an advisory regarding vulnerabilities in its PAN-OS software that affect the Siemens RUGGEDCOM APE1808, utilized in critical manufacturing sectors globally. The vulnerabilities include cross-site scripting, privilege escalation, and command injection, which could allow authenticated users to execute arbitrary commands or store malicious scripts. Users of the RUGGEDCOM APE1808 need to be particularly cautious, as these security flaws could lead to unauthorized access and potential exploitation of the device. Siemens recommends that affected customers consult with their support teams to obtain patches and implement security measures to protect their systems.
Zimbra has released an important update that addresses several serious security vulnerabilities, including command injection, cross-site scripting (XSS), restriction bypass, and server-side request forgery (SSRF) issues. These vulnerabilities could allow attackers to execute arbitrary commands, manipulate web pages, bypass security controls, or make unauthorized requests to other services. Users of Zimbra's email and collaboration software should apply this update promptly to protect their systems from potential exploitation. The vulnerabilities are significant as they could lead to unauthorized access to sensitive information or compromise the integrity of the systems involved. Regular updates are essential for maintaining security and preventing breaches.
ABB has identified multiple vulnerabilities in its T-MAC Plus version 4.0-24 software, which could allow attackers to exploit the system in various ways. These vulnerabilities include issues like file disclosure, broken access controls, cross-site scripting (XSS), and an insecure network protocol that could lead to denial-of-service attacks. Affected users are urged to update to version 4.0-25, which contains fixes for these issues. The vulnerabilities are considered serious, with CVSS scores ranging from 7.4 to 9.9, indicating that they pose significant risks to security. Companies using this software should prioritize applying the update to protect their systems from potential exploitation.
The Hacker News
Zimbra has issued a warning regarding a serious vulnerability in its Classic Web Client that could allow attackers to execute malicious code through specially crafted emails. This vulnerability falls under the category of stored cross-site scripting (XSS) and poses a significant risk as it could enable unauthorized actions within a user's session. While the flaw has not yet been assigned a CVE identifier, Zimbra is urging all customers to implement the necessary updates to mitigate this risk. The potential for arbitrary code execution raises alarms about data security and user safety, making it crucial for affected users to take prompt action. Companies that rely on Zimbra for email services should prioritize applying the updates to protect their systems from potential exploitation.
SCM feed for Latest
Zimbra has identified a serious cross-site scripting (XSS) vulnerability in the Classic Web Client of its Collaboration suite, which is widely used by various organizations, including businesses and government entities. The flaw currently does not have a Common Vulnerabilities and Exposures (CVE) ID, making it crucial for users to take immediate action to protect their systems. This vulnerability could allow attackers to execute scripts in the context of a user's browser, potentially leading to data theft or other malicious activity. Organizations relying on Zimbra should prioritize patching this vulnerability to safeguard their information and maintain the integrity of their communications. Without a fix, they remain at risk of exploitation.
Zimbra has issued a warning regarding a serious stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which is commonly used for accessing Zimbra Collaboration. This flaw allows attackers to execute malicious code when users open compromised emails. The company has released version 10.1.19 to address this vulnerability, which currently does not have a CVE ID. Users of the Classic Web Client should update to this latest version as soon as possible to safeguard their mailboxes from potential exploitation. This incident emphasizes the need for prompt software updates to protect sensitive information from cyber threats.
Zimbra has issued a warning to its customers regarding a serious vulnerability in the Classic Web Client of the Zimbra Collaboration suite. This flaw allows for cross-site scripting (XSS) attacks, which could enable attackers to execute malicious scripts in the context of a user's browser. As a result, users' sensitive information could be compromised. The company is urging all users to apply the necessary patches to protect their systems. This vulnerability is particularly concerning for organizations that rely on Zimbra for communication and collaboration, as it could lead to significant security breaches if left unaddressed.
Digi International has identified serious vulnerabilities in several of its products, including the PortServer TS, Digi One SP, and Digi One SP IA. These flaws could allow attackers to bypass authentication, access restricted resources, and even inject malicious scripts into the system. Specifically, CVE-2026-12352 enables unauthenticated users to gain unauthorized access, while CVE-2026-12948 allows authenticated administrators to execute scripts via the web management interface. Users of affected devices, particularly in critical sectors like manufacturing and transportation, are urged to upgrade to newer products or implement immediate security measures to mitigate risks. Failure to address these vulnerabilities could lead to significant security breaches.