Security
Headlines
HeadlinesLatestCVEs

Tag

#php

WordPress WPvivid Backup Path Traversal

WordPress WPvivid Backup plugin versions prior to 0.9.76 suffer from a path traversal vulnerability.

Packet Storm
#vulnerability#web#git#wordpress#intel#php#auth
WordPress Elementor 3.6.2 Shell Upload

WordPress Elementor plugin versions 3.6.0 through 3.6.2 suffer from a remote shell upload vulnerability. This is achieved by sending a request to install Elementor Pro from a user supplied zip file. Any user with Subscriber or more permissions is able to execute this.

Joomla Solidres 2.12.9 Cross Site Scripting

Joomla Solidres extension version 2.12.9 suffers from a cross site scripting vulnerability.

Researchers Report Supply Chain Vulnerability in Packagist PHP Repository

Researchers have disclosed details about a now-patched high-severity security flaw in Packagist, a PHP software package repository, that could have been exploited to mount software supply chain attacks. "This vulnerability allows gaining control of Packagist," SonarSource researcher Thomas Chauchefoin said in a report shared with The Hacker News. Packagist is used by the PHP package manager

CVE-2022-41443: Header injection (SSRF) vulnerability in phpipam

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

CVE-2022-42247: Encode path+fn in browser.php. Fixes #13262 · pfsense/pfsense@73ca674

pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

Joomla MarvikShop ShoppingCart 3.4 Cross Site Scripting

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a suffers from a cross site scripting vulnerability.

Joomla MarvikShop ShoppingCart 3.4 SQL Injection

Joomla MarvikShop ShoppingCart extension version 3.4 suffers from a remote SQL injection vulnerability.

Joomla JKassa ShoppingCart 2.0.0 SQL Injection

Joomla JKassa ShoppingCart extension version 2.0.0 suffers from a remote SQL injection vulnerability.