MariaDB is a popular open-source database system used by many websites to store data like user information, product details, and site content. A security flaw has been identified in two specific older versions of this software: 3.3.18 and 3.4.8.Even if a website uses a standard built-in security tool designed to block malicious database attacks, ...
Continue reading
A security flaw has been found in the JCE editor extension, a common add-on for websites built with the Joomla content management system. If your Joomla site uses this extension, this vulnerability allows people who do not have authorized login access to your site’s admin panel to create new editor user profiles without permission.Attackers can ...
Continue reading
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass ...
Continue reading
A security flaw has been identified in specific versions of PHP, the open-source software that powers most dynamic websites. The issue impacts PHP 8.4.* releases older than 8.4.21 and PHP 8.5.* releases older than 8.5.6.The vulnerability is triggered when a specially crafted input containing a hidden null byte is sent to common PHP tools used for ...
Continue reading