A security flaw has been identified in the JCE Editor extension, a common add-on for the Joomla website building platform. This issue allows people who do not have login access to your site (unauthenticated users) to create new, unauthorized editor profiles on your Joomla installation without permission.Once these fake profiles are set up, ...
Continue reading
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg ...
Continue reading
A security vulnerability has been found in Twig, a tool used by many websites to render dynamic page content. The flaw affects Twig versions 2.16.x and 3.9.0 through 3.25.x.If your site uses Twig with sandbox security enabled via a source policy (rather than a global site-wide sandbox setting), an attacker with the ability to edit or add site ...
Continue reading
A security flaw impacts specific versions of PHP, the core software that runs most websites. The affected versions are PHP 8.4 releases older than 8.4.21, and PHP 8.5 releases older than 8.5.6.
The flaw is triggered when specially crafted input containing a hidden null byte is sent to PHP's built-in text encoding tools, which handle converting and ...
Continue reading