Binance Square
LIVE
LIVE
Watch Dog
Haussier
--220 views
Crypto Widget WordPress Plugin Flagged as “Critical” Cybersecurity Risk A crypto widget plugin for the web content management system WordPress was named as a “critical cybersecurity risk” yesterday. A security bulletin released by the Cyber Security Agency of Singapore (CSA) noted that a plugin, called “The Cryptocurrency Widgets – Price Ticker & Coins List” has been identified as a cybersecurity risk and could potentially be exploited to extract sensitive information. The crypto widget obtained a base score of 9.8/10, placing it in the “critical” group of vulnerabilities the CSA uses to refer to vulnerabilities with a minimum score of 9/10. The National Vulnerability Database (NVD), the U.S. government repository for standards-based vulnerability management data, said that the WordPress crypto plugin is susceptible to SQL Injection through the ‘coinslist’ parameter in versions 2.0 to 2.6.5. This vulnerability arose from insufficient escaping on the user-supplied parameter and inadequate preparation on the existing SQL query. It permitted the extraction of sensitive information from the database, enabling unauthenticated attackers to add additional structured language queries to the existing ones. According to the security firm CVE Program, the widget was supplied by a vendor identified as “narinder-singh,” and versions 2.0 through 2.6.5 were identified as containing the vulnerability. #cybersecurity #Write2Earn #CryptoGuidance $BTC

Crypto Widget WordPress Plugin Flagged as “Critical” Cybersecurity Risk

A crypto widget plugin for the web content management system WordPress was named as a “critical cybersecurity risk” yesterday.

A security bulletin released by the Cyber Security Agency of Singapore (CSA) noted that a plugin, called “The Cryptocurrency Widgets – Price Ticker & Coins List” has been identified as a cybersecurity risk and could potentially be exploited to extract sensitive information.

The crypto widget obtained a base score of 9.8/10, placing it in the “critical” group of vulnerabilities the CSA uses to refer to vulnerabilities with a minimum score of 9/10.

The National Vulnerability Database (NVD), the U.S. government repository for standards-based vulnerability management data, said that the WordPress crypto plugin is susceptible to SQL Injection through the ‘coinslist’ parameter in versions 2.0 to 2.6.5.

This vulnerability arose from insufficient escaping on the user-supplied parameter and inadequate preparation on the existing SQL query. It permitted the extraction of sensitive information from the database, enabling unauthenticated attackers to add additional structured language queries to the existing ones.

According to the security firm CVE Program, the widget was supplied by a vendor identified as “narinder-singh,” and versions 2.0 through 2.6.5 were identified as containing the vulnerability.

#cybersecurity #Write2Earn #CryptoGuidance $BTC

Avertissement : comprend des opinions de tiers. Il ne s’agit pas d’un conseil financier. Peut inclure du contenu sponsorisé. Consultez les CG.
0
Découvrez les dernières actus sur les cryptos
⚡️ Prenez part aux dernières discussions sur les cryptos
💬 Interagissez avec vos créateur(trice)s préféré(e)s
👍 Profitez du contenu qui vous intéresse
Adresse e-mail/Numéro de téléphone
Créateur pertinent
LIVE
@Square-Creator-077828139

Découvrez-en plus sur le créateur

--
Crypto at the Center of $300M Fraud Case in China. 21 people were sentenced in a case involving converting 'dirty' $USDC to RMB. A court in Tongliang, #China – located near Chongqing – has sentenced 21 people for their role in transferring the proceeds of online fraud and illegal casinos denominated in Tether (USDT) to Chinese Yuan (RMB), totaling 2.25 billion RMB ($307 million). According to a bulletin from the court, two defendants, with the surnames Jiang and Zheng, worked to recruit 19 other money mules. The group, according to court documents, used a decentralized wallet called Bitpie (similar to Metamask) to move the USDT to local P2P exchanges on virtual currency platforms to convert it to Reminbi. They then withdrew the fiat currency in different cities around the country using false pretenses like project payments and workers’ wages when asked for a reason for the transfer. Court documents say that Jiang profited 22.62 million RMB ($3 million) for his efforts. The court found the group guilty of disguising and concealing criminal proceeds, sentencing them to various prison terms and imposing fines, with Jiang getting six years, three months, and a 500,000 RMB fine. In comparison, Zheng was also fined the exact amount and was sentenced to 6 years. Although the court document isn’t specific about where this USDT came from, it’s a popular digital asset used by fraud rings operating in Southeast Asia. In his new book, Number Go Up, Bloomberg journalist Zeke Faux documents how these gangs are effectively powered by Tether. #Write2Earn #Scams $BTC $ETH
--

Dernières actualités

Voir plus
Plan du site
Cookie Preferences
CGU de la plateforme