A security vulnerability has been identified in specific versions of PHP, the core programming language that powers most dynamic websites. The flaw impacts PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The issue is located in PHP's SOAP extension, a tool used ...
Continue reading
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ...
Continue reading
There is a known security vulnerability affecting Microsoft SharePoint, a platform many businesses use for document storage, team collaboration, and internal workflow management on their hosted services. The flaw exists in how SharePoint processes untrusted, unvetted data sent to the system, which can be manipulated by malicious actors.
If this ...
Continue reading
A security flaw has been found in Check Point SmartConsole, a tool some businesses use to manage their network security settings and policies. This is an improper authentication vulnerability, meaning the tool’s built-in checks to confirm only approved users can log in are not working correctly.Because of this issue, an unauthorized person ...
Continue reading