The cyber security experts: There are two vulnerabilities linked to insufficient sanitization of user-supplied data, that pose risks of XSS scripting and SQL Injection. Update it!
Nine of them were “Critical”, the others “Important” or “Moderate”. The first could allow an attacker to take control of an affected system, thanks to RCS. UPDATE the systems now!
Google’s Project Zero expert Maddie Stone: The flaw is related to at least 18 phones models. It can give attackers full control of the phone and it’s being exploiting in the wild.
Sucuri cyber security experts: It’s extremely severe and to date there are no official patches. The payload used modifies the vulnerable snippet by adding a password validation.
The WordFence cyber security experts and the developers fixed it. Authenticated attackers could have remotely execute PHP code. It’s imperative e to update to version 2.4.22.
The cyber security experts of WordFence and the developers, however, fixed it before publishing the news. Users have to upgrade to 3.4.3 version ASAP to avoid cybercrime attacks.
Cyber security expert Luka Šikić of WebARX: The flaw could allow attackers to modify the installation options. There is a patch, the plugin has to be updated ASAP.
Wandera: A vulnerability in the e-ticketing systems could expose PII to malicious hackers. Less than a month ago a major security breach affected more than 140 companies.