CVE-2023-43770 – Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
https://notcve.org/view.php?id=CVE-2023-43770
Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages. • https://github.com/s3cb0y/CVE-2023-43770-POC https://github.com/knight0x07/CVE-2023-43770-PoC https://github.com/roundcube/roundcubemail/commit/e92ec206a886461245e1672d8530cc93c618a49b https://lists.debian.org/debian-lts-announce/2023/09/msg00024.html https://roundcube.net/news/2023/09/15/security-update-1.6.3-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-38718 – IBM Robotic Process Automation information disclosure
https://notcve.org/view.php?id=CVE-2023-38718
IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606. IBM Robotic Process Automation 21.0.0 a 21.0.7.8 podría revelar información sensible procedente del acceso a scripts de RPA, flujos de trabajo y datos relacionados. ID de IBM X-Force: 261606. • https://exchange.xforce.ibmcloud.com/vulnerabilities/261606 https://www.ibm.com/support/pages/node/7031619 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-40368 – IBM Storage Protect information disclosure
https://notcve.org/view.php?id=CVE-2023-40368
IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456. IBM Storage Protect 8.1.0.0 a 8.1.19.0 podría permitir que un usuario privilegiado obtenga información sensible del cliente de línea de comando administrativo. ID de IBM X-Force: 263456. • https://exchange.xforce.ibmcloud.com/vulnerabilities/263456 https://www.ibm.com/support/pages/node/7034288 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-5042
https://notcve.org/view.php?id=CVE-2023-5042
Sensitive information disclosure due to insecure folder permissions. • https://security-advisory.acronis.com/advisories/SEC-5330 • CWE-276: Incorrect Default Permissions •
CVE-2023-4088 – Malicious Code Execution Vulnerability in FA Engineering Software Products
https://notcve.org/view.php?id=CVE-2023-4088
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than the default installation folder. • https://jvn.jp/vu/JVNVU96447193/index.html https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-03 https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-010_en.pdf • CWE-276: Incorrect Default Permissions •