Monthly Archive: April 2020

CVE-2020-12079

Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron...

CVE-2020-12077

The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution. Date published : 2020-04-22 MapPress Maps for WordPress Critical Vulnerabilities Patched...

CVE-2020-12076

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS. Date published : 2020-04-22 Vulnerabilities Patched in the Data Tables Generator by Supsystic...

CVE-2020-12075

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. Date published : 2020-04-22 Vulnerabilities Patched in the Data Tables Generator by Supsystic Plugin

CVE-2020-12074

The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. Date published : 2020-04-22 Vulnerability Patched in Import Export WordPress Users

CVE-2020-12073

The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. Date published : 2020-04-22 Severe Flaws Patched in Responsive Ready Sites Importer Plugin

CVE-2020-11938

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2. Date published : 2020-04-22 JetBrains Security Bulletin Q1...

CVE-2020-11796

In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. Date published : 2020-04-22 JetBrains Security Bulletin Q1 2020

CVE-2020-11795

In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. Date published : 2020-04-22 JetBrains Security Bulletin Q1 2020

CVE-2020-11693

JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. Date published : 2020-04-22 JetBrains Security Bulletin Q1 2020

CVE-2020-11692

In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. Date published : 2020-04-22 JetBrains Security Bulletin Q1 2020