meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, July 18th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 July 2023

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exploited Vulnerabilities in Zimbra, WooCommerce, Coldfusion; CISA free cloud tools; Jumpcloud Breach

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, July 18, 2023 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.8

Well, today we got a couple of different war on abilities to report about it are already being exploited.

0:23.2

Let's start with Simbra.

0:31.8

Simbra, the collaboration suite, published a blog post that in version 8815, there is cross-sad scripting vulnerability that is actively being exploited.

0:37.3

Apparently, some attacks against systems in

0:39.7

the Ukraine used this particular vulnerability. However, there is no simple patch. If you're reading

0:47.5

the Simpra block, it basically just advises you to edit a particular file and well what the edit does is probably what

0:56.7

it should do and that's just escape XML so basically properly escape this pre-filled parameter in a

1:04.7

form that will then prevent the particular cross-site scripting vulnerability from being exploited.

1:12.9

Second vulnerability is older, that's WooCommerce vulnerability that was patched back in March,

1:22.5

but again, is now actively being exploited.

1:26.5

WooCommerce is a payment plugin that works with Verde Breast,

1:32.0

so somewhat popular to create these.

1:37.4

The second vulnerability is a little bit older vulnerability, CVE 2020, 23, 28121.

1:49.9

It's a vulnerability in WooCommerce. WooCommerce is a WordPress plugin that's frequently used to sort of build online stores on top of WordPress. Back in March,

1:58.0

critical vulnerability was patched in WooCommerce that allows authentication bypass.

2:05.4

Essentially, any user may become an administrator exploiting this vulnerability.

2:12.6

Beginning of July, RCE security published some details about how to exploit this vulnerability.

2:20.6

Looks like attackers were listening and now are exploiting this particular problem.

2:27.6

It's actually one of those real simple ones where you set a specific header, essentially, to become

2:33.4

administrator. So really easy to exploit once you know. you set a specific header essentially to become administrator,

2:35.0

so really easy to exploit once you know how to do it.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.