A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.
Articles tagged "XSS"
Found 25 articles
Researchers at Pwn have identified a serious vulnerability in WordPress, dubbed the XSS2Shell flaw, which allows attackers to take control of an admin account and execute remote code. The issue arises when a user inputs a non-existent username, triggering a response from WordPress that contains a minor formatting error. This flaw can be exploited to gain unauthorized access to the server. WordPress users are strongly advised to update their installations to the patched versions to protect against this vulnerability. Failure to do so could leave sites open to full server takeover, posing significant risks to website security and data integrity.
WordPress has addressed a serious vulnerability in its login screen that affects all versions of the platform. This flaw, known as CVE-2026-64638 and rated with a CVSS score of 8.9, allows for pre-authentication reflected cross-site scripting (XSS). Researchers from pwn.ai have demonstrated that this vulnerability could potentially be exploited to execute PHP code on the server, particularly if an administrator interacts with a malicious page. As this issue impacts every WordPress installation, users and website administrators are strongly encouraged to apply the patch immediately to secure their sites and prevent potential exploitation.
Johnson Controls has identified multiple vulnerabilities in their OpenBlue Employee software, specifically versions up to V2025.3.1. These flaws could allow attackers to upload malicious files, execute cross-site scripting (XSS) attacks, or inject harmful HTML content, posing significant risks to users. The vulnerabilities are particularly concerning as they affect critical infrastructure sectors, including manufacturing, transportation, and energy. Johnson Controls advises users to apply the latest updates and implement strong access controls to mitigate potential risks. The company has outlined specific defensive measures to help secure the application and protect users from exploitation.
Zimbra has released an update to fix several serious security vulnerabilities, including a command injection flaw in its Simple Network Management Protocol (SNMP) component. The update, version 10.1.20, addresses a total of nine vulnerabilities, with the SNMP issue being particularly concerning as it could allow attackers to execute unauthorized commands when SNMP notifications are enabled. This could potentially expose sensitive data or disrupt services for organizations using Zimbra's platform. Companies that rely on Zimbra for email and collaboration tools need to update their systems promptly to mitigate these risks and ensure their environments remain secure.
Palo Alto Networks has issued an advisory regarding vulnerabilities in its PAN-OS software that affect the Siemens RUGGEDCOM APE1808, utilized in critical manufacturing sectors globally. The vulnerabilities include cross-site scripting, privilege escalation, and command injection, which could allow authenticated users to execute arbitrary commands or store malicious scripts. Users of the RUGGEDCOM APE1808 need to be particularly cautious, as these security flaws could lead to unauthorized access and potential exploitation of the device. Siemens recommends that affected customers consult with their support teams to obtain patches and implement security measures to protect their systems.
Zimbra has released an important update that addresses several serious security vulnerabilities, including command injection, cross-site scripting (XSS), restriction bypass, and server-side request forgery (SSRF) issues. These vulnerabilities could allow attackers to execute arbitrary commands, manipulate web pages, bypass security controls, or make unauthorized requests to other services. Users of Zimbra's email and collaboration software should apply this update promptly to protect their systems from potential exploitation. The vulnerabilities are significant as they could lead to unauthorized access to sensitive information or compromise the integrity of the systems involved. Regular updates are essential for maintaining security and preventing breaches.
ABB has identified multiple vulnerabilities in its T-MAC Plus version 4.0-24 software, which could allow attackers to exploit the system in various ways. These vulnerabilities include issues like file disclosure, broken access controls, cross-site scripting (XSS), and an insecure network protocol that could lead to denial-of-service attacks. Affected users are urged to update to version 4.0-25, which contains fixes for these issues. The vulnerabilities are considered serious, with CVSS scores ranging from 7.4 to 9.9, indicating that they pose significant risks to security. Companies using this software should prioritize applying the update to protect their systems from potential exploitation.
The Hacker News
Zimbra has issued a warning regarding a serious vulnerability in its Classic Web Client that could allow attackers to execute malicious code through specially crafted emails. This vulnerability falls under the category of stored cross-site scripting (XSS) and poses a significant risk as it could enable unauthorized actions within a user's session. While the flaw has not yet been assigned a CVE identifier, Zimbra is urging all customers to implement the necessary updates to mitigate this risk. The potential for arbitrary code execution raises alarms about data security and user safety, making it crucial for affected users to take prompt action. Companies that rely on Zimbra for email services should prioritize applying the updates to protect their systems from potential exploitation.
SCM feed for Latest
Zimbra has identified a serious cross-site scripting (XSS) vulnerability in the Classic Web Client of its Collaboration suite, which is widely used by various organizations, including businesses and government entities. The flaw currently does not have a Common Vulnerabilities and Exposures (CVE) ID, making it crucial for users to take immediate action to protect their systems. This vulnerability could allow attackers to execute scripts in the context of a user's browser, potentially leading to data theft or other malicious activity. Organizations relying on Zimbra should prioritize patching this vulnerability to safeguard their information and maintain the integrity of their communications. Without a fix, they remain at risk of exploitation.
Zimbra has issued a warning regarding a serious stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which is commonly used for accessing Zimbra Collaboration. This flaw allows attackers to execute malicious code when users open compromised emails. The company has released version 10.1.19 to address this vulnerability, which currently does not have a CVE ID. Users of the Classic Web Client should update to this latest version as soon as possible to safeguard their mailboxes from potential exploitation. This incident emphasizes the need for prompt software updates to protect sensitive information from cyber threats.
Zimbra has issued a warning to its customers regarding a serious vulnerability in the Classic Web Client of the Zimbra Collaboration suite. This flaw allows for cross-site scripting (XSS) attacks, which could enable attackers to execute malicious scripts in the context of a user's browser. As a result, users' sensitive information could be compromised. The company is urging all users to apply the necessary patches to protect their systems. This vulnerability is particularly concerning for organizations that rely on Zimbra for communication and collaboration, as it could lead to significant security breaches if left unaddressed.
Siemens has identified multiple vulnerabilities in its SINEC OS, particularly affecting the RUGGEDCOM RST2428P product. The issues stem from improper input validation, leading to potential allocation failures that could compromise system operations. Siemens has recommended users upgrade to version 4.0 or later to mitigate these risks. The vulnerabilities have been assigned CVE identifiers, indicating their recognition in the cybersecurity community. This situation is significant as it affects industrial control systems, which are critical for operational integrity and security.
Digi International has identified serious vulnerabilities in several of its products, including the PortServer TS, Digi One SP, and Digi One SP IA. These flaws could allow attackers to bypass authentication, access restricted resources, and even inject malicious scripts into the system. Specifically, CVE-2026-12352 enables unauthenticated users to gain unauthorized access, while CVE-2026-12948 allows authenticated administrators to execute scripts via the web management interface. Users of affected devices, particularly in critical sectors like manufacturing and transportation, are urged to upgrade to newer products or implement immediate security measures to mitigate risks. Failure to address these vulnerabilities could lead to significant security breaches.
A newly discovered zero-day vulnerability in Microsoft Exchange, tracked as CVE-2026-42897, poses a significant risk as it allows attackers to exploit cross-site scripting (XSS) to compromise Outlook Web Access (OWA) mailboxes. This vulnerability is reportedly under active attack, meaning that malicious actors are currently trying to exploit it in the wild. Organizations using Microsoft Exchange should be particularly vigilant, as the absence of an available patch leaves their systems exposed. Without immediate remediation, users could face unauthorized access to sensitive email communications. Companies are advised to implement security measures, such as input validation and monitoring for suspicious activity, until an official patch is released.