AcyMailing for Joomla lets anyone email their way to RCE
The mailbox monitoring feature in AcyMailing Enterprise saves email attachments straight into the web root without checking their extension. Fixed in 11.1.0.
Tagged
Everyone knows to eager load. The queries that actually take sites down are the ones hiding in an accessor, a Blade partial, or a policy — and there is a one-line switch that finds all of them.
If your request handler calls somebody else’s API, you have already built a distributed system. The queue is how you stop their bad day from becoming your bad day.
If your mental image of PHP is from 2014, it is wrong in ways that would change your architecture. Here is what actually landed, and which parts change how you write code.
WordPress will happily let you write a query that scans a million meta rows. Here is which arguments are expensive, why, and what to do instead.
The mailbox monitoring feature in AcyMailing Enterprise saves email attachments straight into the web root without checking their extension. Fixed in 11.1.0.
The UP plugin for Joomla fetches action code from GitHub with certificate verification turned off, letting a network-positioned attacker swap in malicious PHP that Joomla then runs. Fixed in 5.2.1 and 6.1.0.
A regex filter meant to block dangerous SQLite commands in Adminer missed statements prefixed with a UTF-8 BOM, letting an authenticated user write PHP straight to a web-accessible directory. Fixed in 6.1.1.
Malcure Malware Shield, installed on more than 10,000 sites, patched a missing-authorization flaw that let multisite subsite admins write and delete arbitrary files, with a path to remote code execution.
Ultra Addons for Contact Form 7 has a critical unauthenticated file upload flaw when its PDF Generator module is switched on. Version 3.5.51 fixes it.
A critical authentication bypass in the miniOrange OTP Login plugin lets an attacker sign in as any administrator with just a username, no password or OTP check required, and there is no fix out yet.
A JWT authentication bypass in WSO2 API Manager and an authorization flaw in Adobe Commerce and Magento are now on the Known Exploited Vulnerabilities catalogue, with a federal patch deadline of 27 September.
A crafted link is enough to trick a logged-in administrator into an unintended action. Update to 4.3.2 if you run the page builder on 10 million sites.
An unauthenticated local file inclusion in template resolution reaches every version back to 4.7. Attackers started probing within hours of the patch.