Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
Remediation
References
Related Vulnerabilities
WordPress Plugin YARPP-Yet Another Related Posts SQL Injection (5.30.2)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.0.0 - 3.9.26)
WordPress Plugin Google Captcha (reCAPTCHA) by BestWebSoft Cross-Site Scripting (1.05)
WordPress Plugin WF Cookie Consent Cross-Site Scripting (1.1.3)
WordPress Plugin EWWW Image Optimizer Denial of Service (6.0.1)