article thumbnail

Drupal developers fixed a code execution flaw in the popular CMS

Security Affairs

The US Cybersecurity and Infrastructure Security Agency (CISA) published an advisory for the above vulnerabilities. . The post Drupal developers fixed a code execution flaw in the popular CMS appeared first on Security Affairs. The most severe one, rated as “critical,” is an arbitrary PHP code execution tracked as CVE-2022-25277.

CMS 109
article thumbnail

HHS OIG: Medicare Should Require Hospital Device Security

Data Breach Today

CMS Says It's Considering New Cybersecurity Requirements The Centers for Medicare and Medicaid Services is considering new cybersecurity requirements for hospitals participating in Medicare after a watchdog agency recommended CMS should require the facilities to address the cybersecurity of their networked medical devices.

CMS 227
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

EnemyBot malware adds new exploits to target CMS servers and Android devices

Security Affairs

LFI CVE-2018-16763 Fuel CMS 1.4.1 ” Security Affairs is one of the finalists for the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS. The post EnemyBot malware adds new exploits to target CMS servers and Android devices appeared first on Security Affairs. Pierluigi Paganini.

CMS 140
article thumbnail

Multiple XSS flaws in Joomla can lead to remote code execution

Security Affairs

Joomla maintainers have addressed multiple vulnerabilities in the popular content management system (CMS) that can lead to execute arbitrary code. The impact of these flaws can be widespread because roughly 2% of all websites use Joomla, millions of websites worldwide use this CMS. The maintainers of the Joomla!

CMS 105
article thumbnail

US CISA added 17 flaws to its Known Exploited Vulnerabilities Catalog

Security Affairs

The Cybersecurity and Infrastructure Security Agency (CISA) this week added seventeen actively exploited vulnerabilities to the Catalog. CVE Number CVE Title Required Action Due Date CVE-2021-32648 October CMS Improper Authentication 2/1/2022 CVE-2021-21315 System Information Library for node.js

CMS 92
article thumbnail

Expert found critical flaws in OpenText Enterprise Content Management System

Security Affairs

Armin Stock (Atos), researcher at cybersecurity firm Sec Consult, discovered multiple vulnerabilities in the OpenText enterprise content management (ECM) product. The OpenText enterprise content management (ECM) system is affected by multiple vulnerabilities, including a critical RCE.

ECM 72
article thumbnail

Russia-linked Turla APT uses new TinyTurla-NG backdoor to spy on Polish NGOs

Security Affairs

The cybersecurity firm identified three different TinyTurla-NG samples, and gained access to two of them. Threat actors compromised the websites running vulnerable versions of the popular CMS, including 4.4.20, 5.0.21, 5.1.18 This latest campaign began at least on December 18, 2023, and was still active as recently as January 27, 2024.

CMS 102