Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Researchers Report Supply Chain Vulnerability in Packagist PHP Repository

Researchers have disclosed details about a now-patched high-severity security flaw in Packagist, a PHP software package repository, that could have been exploited to mount software supply chain attacks. "This vulnerability allows gaining control of Packagist," SonarSource researcher Thomas Chauchefoin said in a report shared with The Hacker News. Packagist is used by the PHP package manager

The Hacker News
#vulnerability#mac#js#git#php#backdoor#auth#The Hacker News
CVE-2022-41443: Header injection (SSRF) vulnerability in phpipam

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

CVE-2022-42247: Encode path+fn in browser.php. Fixes #13262 · pfsense/pfsense@73ca674

pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

Joomla MarvikShop ShoppingCart 3.4 Cross Site Scripting

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a suffers from a cross site scripting vulnerability.

Joomla MarvikShop ShoppingCart 3.4 SQL Injection

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a remote SQL injection vulnerability.

Joomla JKassa ShoppingCart 2.0.0 SQL Injection

Joomla JKassa ShoppingCart extension version 2.0.0 suffers from a remote SQL injection vulnerability.

Joomla Easy Shop 1.4.1 Cross Site Scripting

Joomla Easy Shop extension version 1.4.1 suffers from a cross site scripting vulnerability.

Joomla JUX Charity Hub 1.0.4 SQL Injection

Joomla JUX Charity Hub extension version 1.0.4 suffers from a remote SQL injection vulnerability.

CVE-2022-3125

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE