SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product. Read More
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users. Read More
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin. Read More
Edgar Weippl gave a presentation on Security in Distributed Systems at the technology workshop for the financial industry “Empowered Edge für Banken und Versicherungen”. Read more
Let’s work together to improve cyber security in the European Union! Concordia partners, both from industry and academia, put together their offer for courses aimed at developing cybersecurity skills. “Towards a European Education Ecosystem for Cybersecurity” Concordia at a glance. Read More
Tomasz Miksa gave a keynote on “Engaging researchers with research data management through machine-actionable Data Management Plans” during the “Pomorska Konferencja Open Science (PKOS)” in Gdańsk, Poland. In his talk he discussed challenges in rolling out systems supporting open science and explained why machine-actionable Data Management Plans play… Read More
A group of dedicated young researchers presented their work in the course of the ICT Security Conference on October 1-2, 2019. Katharina Pfeffer (SBA) introduced her research in the area of Usable Security. The conference counting a total of 2500 attendees once more showed that cyber attacks present a… Read More
The 2nd Conference on Urban Resilience, organized by the Czech Informatics, Robotics and Cybernetics Institute (CIIRC), targeted the interdisciplinary approach of fostering technological innovation in an emerging field such as Resilience. In regard to the specific focus on increasing the urban capabilities to tackle present and… Read More
Tomasz Miksa and Bernhard Gößwein presented their paper on Data identification and process monitoring for reproducible earth observation research at the 15th IEEE eScience conference in San Diego. Earth observation researchers use specialised computing services for satellite image processing offered by various data… Read More