CVE-2022-24828 Composer is a dependency manager for PHP that has an integration vulnerability with VcsDriver if the user controls $file or $identifier.
We can only assume that this vulnerability has been used to inject malicious code into the `readme` field of the composer.json file for hg/
CVE-2022-27140 - How a Simple Bug in Express-Fileupload Lets Hackers Upload and Run PHP Files
The world of web development is fast-moving, and sometimes speed means mistakes. One of those costly errors happened in the popular express-fileupload module,
CVE-2022-27263 - Exploiting Arbitrary File Upload in Strapi v4.1.5 — How Attackers Can Execute Code Remotely
Published: June 2024
Overview
CVE-2022-27263 is a severe vulnerability discovered in Strapi, a popular open-source Headless CMS. In version v4.1.5,
CVE-2022-28397 - **DISPUTED** Arbitrary File Upload in Ghost CMS v4.42.—What You Need to Know
---
Overview
A security advisory surfaced about CVE-2022-28397, which raises concerns about an arbitrary file upload vulnerability in the well-known Ghost CMS—specifically
CVE-2022-28346 - How Dictionary Expansion Opened Django to SQL Injection
Django, the famous Python web framework, is known for its robust protection against SQL injection. But in 2022, a serious vulnerability—CVE-2022-28346—was
Episode
00:00:00
00:00:00