home.social

#crosssitescripting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #crosssitescripting, aggregated by home.social.

fetched live
  1. Security Researcher Exploits Flaw in Pretalx Conference Tool

    A security researcher recently uncovered a vulnerability in pretalx, a popular conference tool, that could let hackers inject malicious code into an organizer's interface, putting sensitive data at risk. This flaw, known as a stored cross-site scripting vulnerability, could be triggered through simple search queries.

    osintsights.com/security-resea

    #CrosssiteScripting #Vulnerability #Cve202641241 #Pretalx #OpensourceSoftware

  2. Microsoft Exchange Servers Targeted in Active Exploitation

    Microsoft has sounded the alarm on a critical vulnerability in on-premise Exchange Servers, known as CVE-2026-42897, that's currently being exploited by hackers - and the company is urging affected users to act fast. A temporary fix is in place, with a permanent patch on the way.

    osintsights.com/microsoft-exch

    #Cve202642897 #MicrosoftExchangeServers #EmergingThreats #SpoofingVulnerability #CrosssiteScripting

  3. Microsoft Warns of Severe Zero-Day Flaw in On-Prem Exchange Servers

    Microsoft just sounded the alarm on a severe zero-day flaw in on-prem Exchange servers, warning that a high-severity vulnerability could let attackers send malicious code to victims via specially crafted emails. This flaw, tracked as CVE-2026-42897, has already been automatically mitigated if the EM Service is enabled,…

    osintsights.com/microsoft-warn

    #ZeroDay #ExchangeServerVulnerability #Cve202642897 #CrosssiteScripting #Microsoft

  4. Microsoft Exchange Servers Targeted by Active CVE-2026-42897 Exploit

    Microsoft warns of a high-severity vulnerability, CVE-2026-42897, in its Exchange Servers, allowing attackers to spoof network communications via a cleverly crafted email. This cross-site scripting flaw has been actively exploited, earning a concerning CVSS score of 8.1.

    osintsights.com/microsoft-exch

    #Cve202642897 #MicrosoftExchange #CrosssiteScripting #SpoofingVulnerability #Exploit

  5. Zimbra Servers Targeted in Ongoing XSS Attacks

    Beware of sneaky phishing emails that can hijack your Zimbra server with just a glance - no clicks or downloads required. A single malicious email can trigger a cross-site scripting attack, thanks to a recently patched vulnerability, CVE-2025-48700.

    osintsights.com/zimbra-servers

    #CrosssiteScripting #Zimbra #Cve202548700 #XssAttacks #EmailExploits

  6. Firefox 148 führt Sanitizer-API ein – neuer Standard gegen XSS-Angriffe

    Die Sanitizer-API standardisiert die Bereinigung von HTML-Code direkt beim Einfügen ins DOM und soll Webentwicklern den Schutz vor Cross-Site-Scripting deutlich erleichtern.

    all-about-security.de/firefox-

    #firefox #API #xss #html #crosssitescripting

  7. r6d4: Heute habe ich mir mal die Möglichkeiten angeschaut Mastodon-Post #XSS sauber in die #jek25 Seite einzubinden. Dazu habe ich einen kleinen spike gebastelt.

    y.lab.nrw/jek25-spike

    \__
    #100DaysofCode #wartenauf39c3 #crosssitescripting

  8. Wird Apple Podcasts als Angriffsweg missbraucht?
    Ein ungewöhnliches Verhalten der Apple-Podcasts-App sorgt derzeit für Fragen. Mehrere Nutzer:innen berichten von automatisch startenden Podcasts zu Religion, Spiritualität und Bildung – ohne erkennbaren Grund.

    Podcasts öffnen sich ohne ersichtlichen
    apfeltalk.de/magazin/news/wird
    #iPhone #News #404Media #Apple #CrossSiteScripting #iOS #macOS #Podcasts #Sicherheit #SixColors #XSS

  9. Wird Apple Podcasts als Angriffsweg missbraucht?
    Ein ungewöhnliches Verhalten der Apple-Podcasts-App sorgt derzeit für Fragen. Mehrere Nutzer:innen berichten von automatisch startenden Podcasts zu Religion, Spiritualität und Bildung – ohne erkennbaren Grund.

    Podcasts öffnen sich ohne ersichtlichen
    apfeltalk.de/magazin/news/wird
    #iPhone #News #404Media #Apple #CrossSiteScripting #iOS #macOS #Podcasts #Sicherheit #SixColors #XSS