Tag
#php
Online Travel Agency System version 1.0 suffers from a remote shell upload vulnerability.
### Summary Pimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).
Taskhub version 2.8.8 suffers from an ignored default credential vulnerability.
Webpay E-Commerce version 1.0 suffers from a remote SQL injection vulnerability.
SPIP version 4.2.9 suffers from a code execution vulnerability.
Online Traffic Offense version 1.0 suffers from a cross site request forgery vulnerability.
Penglead version 2.0 suffers from a cross site scripting vulnerability.
PPDB version 2.4-update 6118-1 suffers from a cross site request forgery vulnerability.
Online Travel Agency System version 1.0 suffers from an arbitrary file upload vulnerability.
The threat of VBA macros has diminished since Microsoft prevented the execution of macros in Microsoft Office documents downloaded from the internet, but not all users are using the latest up-to-date Office versions and can still be vulnerable.