A security flaw called HTTP Request Smuggling has been identified in the inets HTTP server module included with Erlang OTP. This issue occurs because the affected server software does not properly handle duplicate Content-Length headers in incoming web requests: it uses the first listed Content-Length value to parse request data, while common ...
Continue reading
A security vulnerability has been identified in the NGINX JavaScript feature that only impacts specific website configurations. The flaw exists if your site uses the js_fetch_proxy setting configured to pull in visitor-controlled data such as request headers, URL parameters, or cookies, and also uses the ngx.fetch() operation from NGINX ...
Continue reading
MariaDB is a popular open-source database system used by many websites to store data like user information, product details, and site content. A security flaw has been identified in two specific older versions of this software: 3.3.18 and 3.4.8.Even if a website uses a standard built-in security tool designed to block malicious database attacks, ...
Continue reading
A security flaw has been found in the JCE editor extension, a common add-on for websites built with the Joomla content management system. If your Joomla site uses this extension, this vulnerability allows people who do not have authorized login access to your site’s admin panel to create new editor user profiles without permission.Attackers can ...
Continue reading