News

The weakness allows a null byte injected in the username field to bypass authentication and insert malicious Lua code into session files.