Our takePHP Group released security updates for SQL injection in the ext module affecting versions before 8.2.33, 8.3.33, 8.4.24 and 8.5.9. Patch now if you run PHP yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update PHP to 8.2.33, 8.3.33, 8.4.24 or 8.5.9 (or later) immediately; the advisory covers a confirmed SQL injection in an extension.
What this means for you — Lean IT orgs:If you run a website or application on PHP, update to version 8.2.33, 8.3.33, 8.4.24 or 8.5.9 (or newer) as soon as possible.
What this means for you — MSP:Check every client PHP instance (self-hosted or in managed apps) and upgrade to 8.2.33+, 8.3.33+, 8.4.24+ or 8.5.9+; the SQL injection is confirmed.
What this means for you — Researcher:PHP released security updates addressing a confirmed SQL injection in an extension; affected versions are prior to 8.2.33, 8.3.33, 8.4.24 and 8.5.9.