CVE-2022-24775 Guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing, which can be abused to inject untrusted values. The issue is patched.
Another major issue with pugnace/psr7 is the lack of rate limiting. An attacker could make a large number of requests with crafted headers that
CVE-2022-26266 - SQL Injection in Piwigo v12.2. via pwg.users.php – Exploit Details and Analysis
Piwigo is a popular open-source photo gallery software used by thousands to manage and share their photos on the web. In early 2022, a
CVE-2022-25581 - Understanding Classcms v2.5 Arbitrary File Upload – How A Malicious TXT File Can Compromise Your Site
In today’s digital age, website security remains a pressing challenge, especially for content management systems (CMS) deployed all over the web. In early 2022,
CVE-2022-24772 - Exploiting Signature Verification Flaw in node-forge’s PKCS#1 v1.5 Implementation
node-forge (sometimes called just forge) is a popular JavaScript library that implements cryptographic protocols—including full-featured TLS/SSL, and a variety of cryptographic
CVE-2022-26965 - Remote Code Execution in Pluck 4.7.16 via Theme Upload
On March 10, 2022, CVE-2022-26965 was published. It describes a high-severity vulnerability in Pluck CMS, an open-source content management system. Versions
Episode
00:00:00
00:00:00