News

Two updates pushed to the PHP Git server over the weekend added a line that, if run by a PHP-powered website, would have allowed visitors with no authorization to execute code of their choice.
The open-source server-side language is commonly used in web development. The code change was first noticed by contributors Markus Staab, Michael Voříšek, and Jake Birchall.