CVE-2022-40048 Flatpress v1.2.1 contains an RCE vulnerability in the Upload File function.
An attacker can upload a malicious file and cause the application to crash, or execute arbitrary PHP code on the server. This is a critical
CVE-2022-31629 An older PHP version can set a cookie for later use which is treated as a '__Host-' or '__Secure-' cookie.
This can be exploited by malicious or compromised websites to facilitate a cross-site request forgery (CSRF) attack to take control of the affected website.
CVE-2022-31628 PHP versions before 7.4.31, 8.0.24 and 8.1.11 had a bug in the gzip uncompressor that could cause an infinite loop.
This has been fixed in version 7.4.31 and later. For more information, visit the phar uncompressor GitHub page.
XSS in unpacked phar files
CVE-2022-39261 Twig is a PHP template language. Before 1.44.7, 2.15.3, and 3.4.3, if a user inputs a template's name, the Twig interpreter may crash.
If you are using any of these versions, you should upgrade to the latest version of Twig. If you are using a version before 1.
CVE-2022-30935 - How a Broken Random Function in b2evolution Exposes All User Accounts
CVE-2022-30935 is a critical security vulnerability found in b2evolution, a popular open-source content management system (CMS). This flaw allows attackers anywhere on
Episode
00:00:00
00:00:00