Security
Headlines
HeadlinesLatestCVEs

Tag

#php

Printable Staff ID Card Creator System 1.0 Insecure Direct Object Reference

Printable Staff ID Card Creator System version 1.0 suffers from an insecure direct object reference vulnerability.

Packet Storm
#vulnerability#web#windows#google#php#auth#firefox
DragonRank, a Chinese-speaking SEO manipulator service provider

Cisco Talos is disclosing a new threat called “DragonRank” that primarily targets countries in Asia and a few in Europe, operating PlugX and BadIIS for search engine optimization (SEO) rank manipulation.

GHSA-f4wh-359g-4pq7: ThinkPHP deserialization vulnerability

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

GHSA-6j75-5wfj-gh66: Twig has a possible sandbox bypass

### Description Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. The security issue happens when all these conditions are met: * The sandbox is disabled globally; * The sandbox is enabled via a sandboxed `include()` function which references a template name (like `included.twig`) and not a `Template` or `TemplateWrapper` instance; * The included template has been loaded before the `include()` call but in a non-sandbox context (possible as the sandbox has been globally disabled). ### Resolution The patch ensures that the sandbox security checks are always run at runtime. ### Credits We would like to thank Fabien Potencier for reporting and fixing the issue.

Debian Security Advisory 5767-1

Debian Linux Security Advisory 5767-1 - Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code.

PPDB 2.4-update 6118-1 SQL Injection

PPDB version 2.4-update 6118-1 suffers from a remote blind SQL injection vulnerability.