#sqlinjection

9 posts · Last used 4d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 4d ago
CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild. #CISA #KEV #WordPress #Langflow #DDWRT #RCE #SQLInjection https://securityonline.info/cisa-kev-four-exploited-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 5d ago
Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0. #ApacheFineract #SQLInjection #CVE #CoreBanking #InfoSec http://securityonline.info/apache-fineract-sql-injection/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 6d ago
The wp2shell chain turns two WordPress core bugs into unauthenticated RCE on default installs. Update to 6.9.5, 7.0.2, or 6.8.6 immediately. #WordPress #wp2shell #RCE #SQLInjection #RESTAPI #CVE https://securityexpress.info/wp2shell-wordpress-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 18, 2026
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
34
1
55
sedje @sedje@fosstodon.org · Jul 18, 2026
If you're looking at the #Wordpress PoC for https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q at https://github.com/attackercan/wp2shell-poc2 , please be aware that the "check" and "read" PoC do not always work. I assume it was created on an empty Wordpress install (with 0 posts). But if it's populated, the OR SLEEP(3) is short circuited away. Trust your version.php instead. (wp2shell-poc does not have an issue tracker enabled to report this to.) #sqlinjection #vulnerability #cve #infosec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 18, 2026
WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now. #WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec https://securityonline.info/wordpress-pre-auth-rce-cve-2026-63030/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 10, 2026
CVE-2026-1207 is a Django SQL injection flaw (CVSS 8.3) in PostGIS raster lookups. Canada's CCCS says it is exploited in the wild. Patch now. #Django #SQLInjection #CVE20261207 #PostGIS #InfoSec https://securityonline.info/django-sql-injection-cve-2026-1207/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 03, 2026
A public PoC is available for CVE-2026-57517, a critical CVSS 9.8 Control Web Panel SQLi flaw allowing unauthenticated remote code execution. #CVE202657517 #ControlWebPanel #SQLInjection #CyberSecurity #Vulnerability https://securityonline.info/cve-2026-57517-control-web-panel-sqli/?utm_source=mastodon&utm_medium=jetpack_social
0
0
1
Thomas Fricke (he/his) @thomasfricke@23.social · Mar 10, 2026
https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform "The agent mapped the attack surface and found the API documentation publicly exposed — over 200 endpoints, fully documented. Most required authentication. Twenty-two didn't. One of those unprotected endpoints wrote user search queries to the database. The values were safely parameterised, but the JSON keys — the field names — were concatenated directly into SQL." Read and write access to everything. #mckinsey #security #ai #sqlinjection
4
2
11

You've seen all posts