Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3fgr-xjr6-xqm8: code injection in phpxmlrpc/phpxmlrpc

code injection in Wrapper::buildClientWrapperCode via manipulation of the $client argument. It was possible to force the client to access local files or connect to undesired urls instead of the intended target server’s url.

ghsa
#git#php

code injection in phpxmlrpc/phpxmlrpc

High severity GitHub Reviewed Published Nov 28, 2022

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation