NVD disclosure day

Published threat advisories for July 31, 2023

CVE advisoryKnown Exploit

CVE-2023-37580

Zimbra Collaboration Suite Cross-Site Scripting Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Zimbra Collaboration Suite's web client has a vulnerability allowing unauthorized data modification, impacting data confidentiality and integrity. This presents a business risk of sensitive information compromise and operational disruption.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-34842

DedeCMS 5.7.109 Remote Code Execution via Crafted POST Request

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical remote code execution vulnerability exists in DedeCMS, allowing unauthenticated attackers to run arbitrary code via a crafted POST request to `/dede/tpl.php`. This could compromise affected systems. The primary concern is confirming the relevance and exposure of this technology within your environment.

CVE advisoryCRITICAL

CVE-2023-37647

SEMCMS 1.5 SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in SEMCMS content management system's /Ant_Suxin.php file allows unauthenticated attackers to manipulate database queries, potentially leading to unauthorized data access or modification. This issue is relevant for SEMCMS deployments, which are typically internet-facing web services.