Search

Find a vulnerability

Search criteria

    121 vulnerabilities by php

    CERTFR-2026-AVI-1227

    Vulnerability from certfr_avis - Published: 2026-09-24 - Updated: 2026-09-24

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.4.x antérieures à 8.4.26
    PHP PHP PHP versions 8.2.x antérieures à 8.2.34
    PHP PHP PHP versions 8.3.x antérieures à 8.3.35
    PHP PHP PHP versions 8.5.x antérieures à 8.5.11
    References
    Bulletin de sécurité PHP 8.3.35 2026-09-24 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.26",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.34",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.35",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.5.x ant\u00e9rieures \u00e0 8.5.11",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-14181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14181"
        },
        {
          "name": "CVE-2026-91765",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91765"
        },
        {
          "name": "CVE-2026-92842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-92842"
        },
        {
          "name": "CVE-2026-91767",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91767"
        },
        {
          "name": "CVE-2026-91766",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91766"
        },
        {
          "name": "CVE-2026-91769",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91769"
        },
        {
          "name": "CVE-2026-93682",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-93682"
        },
        {
          "name": "CVE-2026-91768",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-91768"
        },
        {
          "name": "CVE-2026-6103",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6103"
        },
        {
          "name": "CVE-2025-1218",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1218"
        },
        {
          "name": "CVE-2026-17545",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-17545"
        }
      ],
      "initial_release_date": "2026-09-24T00:00:00",
      "last_revision_date": "2026-09-24T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1227",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-24T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.35",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.35"
        }
      ]
    }

    CERTFR-2026-AVI-0952

    Vulnerability from certfr_avis - Published: 2026-07-31 - Updated: 2026-07-31

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une injection SQL (SQLi), un déni de service et un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.3.x antérieures à 8.3.33
    PHP PHP PHP versions 8.5.x antérieures à 8.5.9
    PHP PHP PHP versions 8.4.x antérieures à 8.4.24
    PHP PHP PHP versions 8.2.x antérieures à 8.2.33
    References
    Bulletin de sécurité PHP 8.5.9 2026-07-30 vendor-advisory
    Bulletin de sécurité PHP 8.2.33 2026-07-30 vendor-advisory
    Bulletin de sécurité PHP 8.3.33 2026-07-30 vendor-advisory
    Bulletin de sécurité PHP 8.4.24 2026-07-30 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.33",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.5.x ant\u00e9rieures \u00e0 8.5.9",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.24",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.33",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-7260",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7260"
        },
        {
          "name": "CVE-2026-17543",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-17543"
        },
        {
          "name": "CVE-2026-17544",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-17544"
        },
        {
          "name": "CVE-2026-9672",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9672"
        }
      ],
      "initial_release_date": "2026-07-31T00:00:00",
      "last_revision_date": "2026-07-31T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0952",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-31T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Injection SQL (SQLi)"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "D\u00e9ni de service"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une injection SQL (SQLi), un d\u00e9ni de service et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2026-07-30",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.5.9",
          "url": "https://www.php.net/ChangeLog-8.php#8.5.9"
        },
        {
          "published_at": "2026-07-30",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.33",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.33"
        },
        {
          "published_at": "2026-07-30",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.33",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.33"
        },
        {
          "published_at": "2026-07-30",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.24",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.24"
        }
      ]
    }

    CERTFR-2026-AVI-0843

    Vulnerability from certfr_avis - Published: 2026-07-07 - Updated: 2026-07-07

    De multiples vulnérabilités ont été découvertes dans PHP. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.5.x antérieures à 8.5.8
    PHP PHP PHP versions 8.3.x antérieures à 8.3.32
    PHP PHP PHP versions 8.2.x antérieures à 8.2.32
    PHP PHP PHP versions 8.4.x antérieures à 8.4.23
    References
    Bulletin de sécurité PHP 8.4.23 2026-07-02 vendor-advisory
    Bulletin de sécurité PHP 8.5.8 2026-07-02 vendor-advisory
    Bulletin de sécurité PHP 8.3.32 2026-07-02 vendor-advisory
    Bulletin de sécurité PHP 8.2.32 2026-07-02 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.5.x ant\u00e9rieures \u00e0 8.5.8",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.32",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.32",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.23",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-14355",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-14355"
        },
        {
          "name": "CVE-2026-12184",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-12184"
        }
      ],
      "initial_release_date": "2026-07-07T00:00:00",
      "last_revision_date": "2026-07-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0843",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-07-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2026-07-02",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.23",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.23"
        },
        {
          "published_at": "2026-07-02",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.5.8",
          "url": "https://www.php.net/ChangeLog-8.php#8.5.8"
        },
        {
          "published_at": "2026-07-02",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.32",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.32"
        },
        {
          "published_at": "2026-07-02",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.32",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.32"
        }
      ]
    }

    CERTFR-2026-AVI-0553

    Vulnerability from certfr_avis - Published: 2026-05-11 - Updated: 2026-05-11

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une injection SQL (SQLi) et une injection de code indirecte à distance (XSS).

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.2.x antérieures à 8.2.31
    PHP PHP PHP versions 8.4.x antérieures à 8.4.21
    PHP PHP PHP versions 8.5.x antérieures à 8.5.6
    PHP PHP PHP versions 8.3.x antérieures à 8.3.31
    References
    Bulletin de sécurité PHP 8.4.21 2026-05-07 vendor-advisory
    Bulletin de sécurité PHP 8.5.6 2026-05-07 vendor-advisory
    Bulletin de sécurité PHP 8.3.31 2026-05-07 vendor-advisory
    Bulletin de sécurité PHP 8.2.31 2026-05-07 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.31",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.21",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.5.x ant\u00e9rieures \u00e0 8.5.6",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.31",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-7261",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7261"
        },
        {
          "name": "CVE-2026-6104",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6104"
        },
        {
          "name": "CVE-2026-6735",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6735"
        },
        {
          "name": "CVE-2025-14179",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14179"
        },
        {
          "name": "CVE-2026-7568",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7568"
        },
        {
          "name": "CVE-2026-6722",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6722"
        },
        {
          "name": "CVE-2026-7258",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7258"
        },
        {
          "name": "CVE-2026-42371",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42371"
        },
        {
          "name": "CVE-2026-7259",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7259"
        },
        {
          "name": "CVE-2026-7262",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7262"
        },
        {
          "name": "CVE-2026-7263",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7263"
        }
      ],
      "initial_release_date": "2026-05-11T00:00:00",
      "last_revision_date": "2026-05-11T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0553",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-05-11T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Injection SQL (SQLi)"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une injection SQL (SQLi) et une injection de code indirecte \u00e0 distance (XSS).",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2026-05-07",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.21",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.21"
        },
        {
          "published_at": "2026-05-07",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.5.6",
          "url": "https://www.php.net/ChangeLog-8.php#8.5.6"
        },
        {
          "published_at": "2026-05-07",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.31",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.31"
        },
        {
          "published_at": "2026-05-07",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.31",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.31"
        }
      ]
    }

    CERTFR-2025-AVI-1126

    Vulnerability from certfr_avis - Published: 2025-12-19 - Updated: 2025-12-22

    De multiples vulnérabilités ont été découvertes dans PHP. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.3.x antérieures à 8.3.29
    PHP PHP PHP versions 8.4.x antérieures à 8.4.16
    PHP PHP PHP versions 8.5.x antérieures à 8.5.1
    PHP PHP PHP versions 8.2.x antérieures à 8.2.30
    PHP PHP PHP versions 8.1.x antérieures à 8.1.34
    References
    Bulletin de sécurité PHP 8.1.34 2025-12-18 vendor-advisory
    Bulletin de sécurité PHP 8.3.29 2025-12-18 vendor-advisory
    Bulletin de sécurité PHP 8.4.16 2025-12-18 vendor-advisory
    Bulletin de sécurité PHP 8.2.30 2025-12-18 vendor-advisory
    Bulletin de sécurité PHP 8.5.1 2025-12-18 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.29",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.16",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.5.x ant\u00e9rieures \u00e0 8.5.1",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.30",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.1.x ant\u00e9rieures \u00e0 8.1.34",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-14177",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14177"
        },
        {
          "name": "CVE-2025-67899",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-67899"
        },
        {
          "name": "CVE-2025-14180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14180"
        },
        {
          "name": "CVE-2025-14178",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14178"
        }
      ],
      "initial_release_date": "2025-12-19T00:00:00",
      "last_revision_date": "2025-12-22T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1126",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-12-19T00:00:00.000000"
        },
        {
          "description": "Ajout version 8.1.34",
          "revision_date": "2025-12-22T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2025-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.1.34",
          "url": "https://www.php.net/ChangeLog-8.php#8.1.34"
        },
        {
          "published_at": "2025-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.29",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.29"
        },
        {
          "published_at": "2025-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.16",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.16"
        },
        {
          "published_at": "2025-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.30",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.30"
        },
        {
          "published_at": "2025-12-18",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.5.1",
          "url": "https://www.php.net/ChangeLog-8.php#8.5.1"
        }
      ]
    }

    CERTFR-2025-AVI-0558

    Vulnerability from certfr_avis - Published: 2025-07-04 - Updated: 2025-07-04

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une injection SQL (SQLi) et une falsification de requêtes côté serveur (SSRF).

    L'éditeur a connaissance de preuves de concept pour les vulnérabilités CVE-2025-6491 et CVE-2025-1220.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.4.x antérieures à 8.4.10
    PHP PHP PHP versions 8.2.x antérieures à 8.2.29
    PHP PHP PHP versions 8.3.x antérieures à 8.3.23
    PHP PHP PHP versions 8.1.x antérieures à 8.1.33
    References
    Bulletin de sécurité PHP 8.4.10 2025-07-03 vendor-advisory
    Bulletin de sécurité PHP 8.1.33 2025-07-03 vendor-advisory
    Bulletin de sécurité PHP 8.3.23 2025-07-03 vendor-advisory
    Bulletin de sécurité PHP 8.2.29 2025-07-03 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.10",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.29",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.23",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.1.x ant\u00e9rieures \u00e0 8.1.33",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-1220",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1220"
        },
        {
          "name": "CVE-2025-6491",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-6491"
        },
        {
          "name": "CVE-2025-1735",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1735"
        }
      ],
      "initial_release_date": "2025-07-04T00:00:00",
      "last_revision_date": "2025-07-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0558",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-07-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection SQL (SQLi)"
        },
        {
          "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une injection SQL (SQLi) et une falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF).\n\nL\u0027\u00e9diteur a connaissance de preuves de concept pour les vuln\u00e9rabilit\u00e9s  CVE-2025-6491 et CVE-2025-1220.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2025-07-03",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.10",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.10"
        },
        {
          "published_at": "2025-07-03",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.1.33",
          "url": "https://www.php.net/ChangeLog-8.php#8.1.33"
        },
        {
          "published_at": "2025-07-03",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.23",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.23"
        },
        {
          "published_at": "2025-07-03",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.29",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.29"
        }
      ]
    }

    CERTFR-2025-AVI-0209

    Vulnerability from certfr_avis - Published: 2025-03-14 - Updated: 2025-03-14

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.3.x antérieures à 8.3.19
    PHP PHP PHP versions 8.2.x antérieures à 8.2.28
    PHP PHP PHP versions 8.4.x antérieures à 8.4.5
    PHP PHP PHP versions 8.1.x antérieures à 8.1.32
    References
    Bulletin de sécurité PHP 8.3.19 2025-03-13 vendor-advisory
    Bulletin de sécurité PHP 8.4.5 2025-03-13 vendor-advisory
    Bulletin de sécurité PHP 8.1.32 2025-03-13 vendor-advisory
    Bulletin de sécurité PHP 8.2.28 2025-03-13 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.19",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.28",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.4.x ant\u00e9rieures \u00e0 8.4.5",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.1.x ant\u00e9rieures \u00e0 8.1.32",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-1217",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1217"
        },
        {
          "name": "CVE-2024-11235",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11235"
        },
        {
          "name": "CVE-2025-1736",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1736"
        },
        {
          "name": "CVE-2025-1734",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1734"
        },
        {
          "name": "CVE-2025-1861",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1861"
        },
        {
          "name": "CVE-2025-1219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-1219"
        }
      ],
      "initial_release_date": "2025-03-14T00:00:00",
      "last_revision_date": "2025-03-14T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0209",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-03-14T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2025-03-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.19",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.19"
        },
        {
          "published_at": "2025-03-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.4.5",
          "url": "https://www.php.net/ChangeLog-8.php#8.4.5"
        },
        {
          "published_at": "2025-03-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.1.32",
          "url": "https://www.php.net/ChangeLog-8.php#8.1.32"
        },
        {
          "published_at": "2025-03-13",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.28",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.28"
        }
      ]
    }

    CERTFR-2024-AVI-1007

    Vulnerability from certfr_avis - Published: 2024-11-21 - Updated: 2024-11-21

    De multiples vulnérabilités ont été découvertes dans les produits PHP. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.3.x antérieures à 8.3.14
    PHP PHP PHP versions 8.1.x antérieures à 8.1.31
    PHP PHP PHP versions 8.2.x antérieures à 8.2.26
    References
    Bulletin de sécurité PHP 8.3.14 2024-11-21 vendor-advisory
    Bulletin de sécurité PHP 8.1.31 2024-11-21 vendor-advisory
    Bulletin de sécurité PHP 8.2.26 2024-11-21 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.14",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.1.x ant\u00e9rieures \u00e0 8.1.31",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.26",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-11236",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11236"
        },
        {
          "name": "CVE-2024-11234",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11234"
        },
        {
          "name": "CVE-2024-8932",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8932"
        },
        {
          "name": "CVE-2024-8929",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8929"
        },
        {
          "name": "CVE-2024-11233",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-11233"
        }
      ],
      "initial_release_date": "2024-11-21T00:00:00",
      "last_revision_date": "2024-11-21T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-1007",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-11-21T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es, une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2024-11-21",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.14",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.14"
        },
        {
          "published_at": "2024-11-21",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.1.31",
          "url": "https://www.php.net/ChangeLog-8.php#8.1.31"
        },
        {
          "published_at": "2024-11-21",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.26",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.26"
        }
      ]
    }

    CERTFR-2024-AVI-0818

    Vulnerability from certfr_avis - Published: 2024-09-27 - Updated: 2024-09-27

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.2.x antérieures à 8.2.24
    PHP PHP PHP versions antérieures à 8.1.30
    PHP PHP PHP versions 8.3.x antérieures à 8.3.12
    References
    Bulletin de sécurité PHP 8.2.24 2024-09-26 vendor-advisory
    Bulletin de sécurité PHP 8.3.12 2024-09-26 vendor-advisory
    Bulletin de sécurité PHP 8.1.30 2024-09-26 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.24",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions ant\u00e9rieures \u00e0 8.1.30",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.12",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-8927",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8927"
        },
        {
          "name": "CVE-2024-8925",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8925"
        },
        {
          "name": "CVE-2024-4577",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-4577"
        },
        {
          "name": "CVE-2024-8926",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-8926"
        },
        {
          "name": "CVE-2024-9026",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-9026"
        }
      ],
      "initial_release_date": "2024-09-27T00:00:00",
      "last_revision_date": "2024-09-27T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0818",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-09-27T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": "2024-09-26",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.24",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.24"
        },
        {
          "published_at": "2024-09-26",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.12",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.12"
        },
        {
          "published_at": "2024-09-26",
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.1.30",
          "url": "https://www.php.net/ChangeLog-8.php#8.1.30"
        }
      ]
    }

    CERTFR-2024-AVI-0300

    Vulnerability from certfr_avis - Published: 2024-04-12 - Updated: 2024-04-12

    De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire et un déni de service.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.3.x antérieures à 8.3.6
    PHP PHP PHP versions 8.2.x antérieures à 8.2.18
    PHP PHP PHP versions 8.1.x antérieures à 8.1.28
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.3.x ant\u00e9rieures \u00e0 8.3.6",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.18",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        },
        {
          "description": "PHP versions 8.1.x ant\u00e9rieures \u00e0 8.1.28",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2024-3096",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-3096"
        },
        {
          "name": "CVE-2024-2756",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2756"
        },
        {
          "name": "CVE-2024-1874",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-1874"
        },
        {
          "name": "CVE-2024-2757",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-2757"
        }
      ],
      "initial_release_date": "2024-04-12T00:00:00",
      "last_revision_date": "2024-04-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0300",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-04-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Certaines\nd\u0027entre elles permettent \u00e0 un attaquant de provoquer un probl\u00e8me de\ns\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur, une ex\u00e9cution de code arbitraire et\nun d\u00e9ni de service.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.3.6 du 11 avril 2024",
          "url": "https://www.php.net/ChangeLog-8.php#8.3.6"
        },
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.18 du 11 avril 2024",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.18"
        }
      ]
    }

    CERTFR-2023-AVI-0669

    Vulnerability from certfr_avis - Published: 2023-08-21 - Updated: 2023-08-21

    De multiples vulnérabilités ont été découvertes dans PHP. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.2.x antérieures à 8.2.9
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.2.x ant\u00e9rieures \u00e0 8.2.9",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-3823",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3823"
        },
        {
          "name": "CVE-2023-3824",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3824"
        }
      ],
      "initial_release_date": "2023-08-21T00:00:00",
      "last_revision_date": "2023-08-21T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0669",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-08-21T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Elles\npermettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non\nsp\u00e9cifi\u00e9 par l\u0027\u00e9diteur et un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.2.9 du 16 ao\u00fbt 2023",
          "url": "https://www.php.net/ChangeLog-8.php#8.2.9"
        }
      ]
    }

    CERTFR-2023-AVI-0628

    Vulnerability from certfr_avis - Published: 2023-08-07 - Updated: 2023-08-07

    De multiples vulnérabilités ont été découvertes dans PHP. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    PHP PHP PHP versions 8.0.x antérieures à 8.0.30
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "PHP versions 8.0.x ant\u00e9rieures \u00e0 8.0.30",
          "product": {
            "name": "PHP",
            "vendor": {
              "name": "PHP",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-3823",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3823"
        },
        {
          "name": "CVE-2023-3824",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3824"
        }
      ],
      "initial_release_date": "2023-08-07T00:00:00",
      "last_revision_date": "2023-08-07T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0628",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-08-07T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans PHP. Elles\npermettent \u00e0 un attaquant de provoquer un probl\u00e8me de s\u00e9curit\u00e9 non\nsp\u00e9cifi\u00e9 par l\u0027\u00e9diteur et un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans PHP",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 PHP 8.0.30 du 04 ao\u00fbt 2023",
          "url": "https://www.php.net/ChangeLog-8.php#8.0.30"
        }
      ]
    }

    CVE-2026-14355 (GCVE-0-2026-14355)

    Vulnerability from cvelistv5 – Published: 2026-07-03 20:57 – Updated: 2026-07-06 13:57
    VLAI
    Title
    ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
    Summary
    In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-06 13:57 UTC
    CWE
    • CWE-122 - Heap-based buffer overflow
    Assigner
    Impacted products
    Vendor Product Version
    php php Affected: 8.2.0 , < 8.2.32 (semver)
    Affected: 8.3.0 , < 8.3.32 (semver)
    Affected: 8.4.0 , < 8.4.23 (semver)
    Affected: 8.5.0 , < 8.5.8 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-07-04T15:25:16.999Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14355",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-06T13:57:51.767008Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-06T13:57:58.387Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://www.php.net/",
              "defaultStatus": "affected",
              "modules": [
                "ext/openssl"
              ],
              "packageName": "openssl",
              "product": "php",
              "vendor": "php",
              "versions": [
                {
                  "lessThan": "8.2.32",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.32",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.4.23",
                  "status": "affected",
                  "version": "8.4.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.5.8",
                  "status": "affected",
                  "version": "8.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Oleg Baturin"
            },
            {
              "lang": "en",
              "type": "remediation developer",
              "value": "David CARLIER"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIn PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.\u003c/p\u003e"
                }
              ],
              "value": "In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122 Heap-based buffer overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-03T20:59:02.604Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "name": "GitHub Security Advisory GHSA-7jrw-539f-x6vr",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr"
            }
          ],
          "source": {
            "advisory": "GHSA-7jrw-539f-x6vr",
            "defenseOmission": false,
            "discovery": "EXTERNAL"
          },
          "title": "ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2026-14355",
        "datePublished": "2026-07-03T20:57:31.958Z",
        "dateReserved": "2026-07-01T17:52:41.706Z",
        "dateUpdated": "2026-07-06T13:57:58.387Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-45062 (GCVE-0-2026-45062)

    Vulnerability from cvelistv5 – Published: 2026-06-10 17:38 – Updated: 2026-06-11 14:00
    VLAI
    Title
    FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
    Summary
    FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a non-.php file as a .php script. In any deployment where the attacker can place content into a file served by FrankenPHP (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This issue has been patched in version 1.12.3.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-11 14:00 UTC
    CWE
    • CWE-20 - Improper Input Validation
    • CWE-176 - Improper Handling of Unicode Encoding
    • CWE-178 - Improper Handling of Case Sensitivity
    References
    Impacted products
    Vendor Product Version
    php frankenphp Affected: >= 1.11.2, < 1.12.3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-45062",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-11T14:00:18.823214Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-11T14:00:50.845Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/php/frankenphp/security/advisories/GHSA-3g8v-8r37-cgjm"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "frankenphp",
              "vendor": "php",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 1.11.2, \u003c 1.12.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a non-.php file as a .php script. In any deployment where the attacker can place content into a file served by FrankenPHP (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This issue has been patched in version 1.12.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20: Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-176",
                  "description": "CWE-176: Improper Handling of Unicode Encoding",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-178",
                  "description": "CWE-178: Improper Handling of Case Sensitivity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-10T17:38:42.454Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/php/frankenphp/security/advisories/GHSA-3g8v-8r37-cgjm",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/php/frankenphp/security/advisories/GHSA-3g8v-8r37-cgjm"
            },
            {
              "name": "https://github.com/php/frankenphp/releases/tag/v1.12.3",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/php/frankenphp/releases/tag/v1.12.3"
            }
          ],
          "source": {
            "advisory": "GHSA-3g8v-8r37-cgjm",
            "discovery": "UNKNOWN"
          },
          "title": "FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-45062",
        "datePublished": "2026-06-10T17:38:42.454Z",
        "dateReserved": "2026-05-08T18:45:10.095Z",
        "dateUpdated": "2026-06-11T14:00:50.845Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24895 (GCVE-0-2026-24895)

    Vulnerability from cvelistv5 – Published: 2026-02-12 19:16 – Updated: 2026-02-12 20:04
    VLAI
    Title
    FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files
    Summary
    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the original path. Because strings.ToLower() in Go can increase the byte length of certain UTF-8 characters (e.g., Ⱥ expands when lowercased), the computed index may not align with the correct position in the original string. This results in an incorrect SCRIPT_NAME and SCRIPT_FILENAME, potentially causing FrankenPHP to execute a file other than the one intended by the URI. This vulnerability is fixed in 1.11.2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-12 20:03 UTC
    CWE
    • CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
    Impacted products
    Vendor Product Version
    php frankenphp Affected: < 1.11.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-12T20:03:49.803836Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-12T20:04:07.435Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "frankenphp",
              "vendor": "php",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.11.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP\u2019s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the original path. Because strings.ToLower() in Go can increase the byte length of certain UTF-8 characters (e.g., \u023a expands when lowercased), the computed index may not align with the correct position in the original string. This results in an incorrect SCRIPT_NAME and SCRIPT_FILENAME, potentially causing FrankenPHP to execute a file other than the one intended by the URI. This vulnerability is fixed in 1.11.2."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-180",
                  "description": "CWE-180: Incorrect Behavior Order: Validate Before Canonicalize",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-12T19:16:06.618Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/php/frankenphp/security/advisories/GHSA-g966-83w7-6w38",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/php/frankenphp/security/advisories/GHSA-g966-83w7-6w38"
            },
            {
              "name": "https://github.com/php/frankenphp/commit/04fdc0c1e8fde94e2c1ad86217e962c88d27c53e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/php/frankenphp/commit/04fdc0c1e8fde94e2c1ad86217e962c88d27c53e"
            },
            {
              "name": "https://github.com/php/frankenphp/releases/tag/v1.11.2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/php/frankenphp/releases/tag/v1.11.2"
            }
          ],
          "source": {
            "advisory": "GHSA-g966-83w7-6w38",
            "discovery": "UNKNOWN"
          },
          "title": "FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-24895",
        "datePublished": "2026-02-12T19:16:06.618Z",
        "dateReserved": "2026-01-27T19:35:20.529Z",
        "dateUpdated": "2026-02-12T20:04:07.435Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24894 (GCVE-0-2026-24894)

    Vulnerability from cvelistv5 – Published: 2026-02-12 19:12 – Updated: 2026-02-12 20:04
    VLAI
    Title
    FrankenPHP leaks session data between requests in worker mode
    Summary
    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-12 20:04 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    • CWE-384 - Session Fixation
    • CWE-613 - Insufficient Session Expiration
    Impacted products
    Vendor Product Version
    php frankenphp Affected: < 1.11.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24894",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-12T20:04:24.224705Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-12T20:04:57.869Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "frankenphp",
              "vendor": "php",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.11.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentially belonging to a different user) before session_start() is called. This vulnerability is fixed in 1.11.2."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-384",
                  "description": "CWE-384: Session Fixation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613: Insufficient Session Expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-12T19:12:04.387Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/php/frankenphp/security/advisories/GHSA-r3xh-3r3w-47gp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/php/frankenphp/security/advisories/GHSA-r3xh-3r3w-47gp"
            },
            {
              "name": "https://github.com/php/frankenphp/commit/24d6c991a7761b638190eb081deae258143e9735",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/php/frankenphp/commit/24d6c991a7761b638190eb081deae258143e9735"
            },
            {
              "name": "https://github.com/php/frankenphp/releases/tag/v1.11.2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/php/frankenphp/releases/tag/v1.11.2"
            }
          ],
          "source": {
            "advisory": "GHSA-r3xh-3r3w-47gp",
            "discovery": "UNKNOWN"
          },
          "title": "FrankenPHP leaks session data between requests in worker mode"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-24894",
        "datePublished": "2026-02-12T19:12:04.387Z",
        "dateReserved": "2026-01-27T19:35:20.529Z",
        "dateUpdated": "2026-02-12T20:04:57.869Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-48580 (GCVE-0-2024-48580)

    Vulnerability from cvelistv5 – Published: 2024-10-25 00:00 – Updated: 2024-10-25 19:44
    VLAI
    Summary
    SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-25 19:32 UTC
    CWE
    • n/a
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    php best_courier_management_system Affected: 1.0
        cpe:2.3:a:php:best_courier_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:best_courier_management_system:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "best_courier_management_system",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-48580",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-25T19:32:30.400940Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-25T19:44:15.354Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-25T15:43:48.104Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/baineoli/CVE/blob/main/2024/courier%20management%20system%20-%20SQL%20Injection%20%28Admin%20Login%29.md"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-48580",
        "datePublished": "2024-10-25T00:00:00.000Z",
        "dateReserved": "2024-10-08T00:00:00.000Z",
        "dateUpdated": "2024-10-25T19:44:15.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-48581 (GCVE-0-2024-48581)

    Vulnerability from cvelistv5 – Published: 2024-10-25 00:00 – Updated: 2024-10-25 19:47
    VLAI
    Summary
    File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-25 19:45 UTC
    CWE
    • n/a
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    php best_courier_management_system Affected: 1.0
        cpe:2.3:a:php:best_courier_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:best_courier_management_system:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "best_courier_management_system",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-48581",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-25T19:45:33.491486Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-25T19:47:50.410Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-25T15:39:39.513Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/baineoli/CVE/blob/main/2024/courier%20management%20system%20-%20Unrestricted%20File%20Upload%20to%20RCE%20%28Sign%20Up%29.md"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-48581",
        "datePublished": "2024-10-25T00:00:00.000Z",
        "dateReserved": "2024-10-08T00:00:00.000Z",
        "dateUpdated": "2024-10-25T19:47:50.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-48579 (GCVE-0-2024-48579)

    Vulnerability from cvelistv5 – Published: 2024-10-25 00:00 – Updated: 2024-10-25 19:52
    VLAI
    Summary
    SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-25 19:49 UTC
    CWE
    • n/a
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    php best_house_rental_management_system Affected: 1.0
        cpe:2.3:a:php:best_house_rental_management_system:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:best_house_rental_management_system:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "best_house_rental_management_system",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-48579",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-25T19:49:42.781625Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-25T19:52:05.379Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-25T15:35:54.644Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/baineoli/CVE/blob/main/2024/house%20rental%20management%20system%20-%20SQL%20Injection%20%28Admin%20Login%29.md"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-48579",
        "datePublished": "2024-10-25T00:00:00.000Z",
        "dateReserved": "2024-10-08T00:00:00.000Z",
        "dateUpdated": "2024-10-25T19:52:05.379Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9026 (GCVE-0-2024-9026)

    Vulnerability from cvelistv5 – Published: 2024-10-08 04:07 – Updated: 2025-11-03 22:33
    VLAI
    Title
    PHP-FPM logs from children may be altered
    Summary
    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-08 12:47 UTC
    CWE
    • CWE-158 - Improper Neutralization of Null Byte or NUL Character
    • CWE-117 - Improper Output Neutralization for Logs
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.30 (semver)
    Affected: 8.2.* , < 8.2.24 (semver)
    Affected: 8.3.* , < 8.3.12 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.30 (semver)
    Affected: 8.2.0 , < 8.2.24 (semver)
    Affected: 8.3.0 , < 8.3.12 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-27 17:50
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.30",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.24",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.12",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9026",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-08T12:47:58.418408Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-08T13:52:08.340Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:15.254Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20241101-0003/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.30",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.24",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.12",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "S\u00e9bastien Rolland"
            }
          ],
          "datePublic": "2024-09-27T17:50:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is\u0026nbsp;configured to catch workers output through catch_workers_output = yes,\u0026nbsp;it may be possible to pollute the final log or\u0026nbsp;remove up to 4 characters from the log messages by manipulating log message content. Additionally, if\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ePHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is\u00a0configured to catch workers output through catch_workers_output = yes,\u00a0it may be possible to pollute the final log or\u00a0remove up to 4 characters from the log messages by manipulating log message content. Additionally, if\u00a0PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-268",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-268 Audit Log Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 3.3,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-158",
                  "description": "CWE-158: Improper Neutralization of Null Byte or NUL Character",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-117",
                  "description": "CWE-117: Improper Output Neutralization for Logs",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-08T04:07:33.452Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-865w-9rf3-2wh5"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "PHP-FPM logs from children may be altered",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-9026",
        "datePublished": "2024-10-08T04:07:33.452Z",
        "dateReserved": "2024-09-20T00:15:42.321Z",
        "dateUpdated": "2025-11-03T22:33:15.254Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-8927 (GCVE-0-2024-8927)

    Vulnerability from cvelistv5 – Published: 2024-10-08 03:56 – Updated: 2025-11-03 22:33
    VLAI
    Title
    cgi.force_redirect configuration is bypassable due to the environment variable collision
    Summary
    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-08 12:50 UTC
    CWE
    • CWE-1220 - Insufficient Granularity of Access Control
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.30 (semver)
    Affected: 8.2.* , < 8.2.24 (semver)
    Affected: 8.3.* , < 8.3.12 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.30 (semver)
    Affected: 8.2.0 , < 8.2.24 (semver)
    Affected: 8.3.0 , < 8.3.12 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-27 17:50
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.30",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.24",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.12",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8927",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-08T12:50:40.800289Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-1220",
                    "description": "CWE-1220 Insufficient Granularity of Access Control",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-18T16:16:00.693Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:09.411Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20241101-0003/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.30",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.24",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.12",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Owen Gong"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "RyotaK"
            }
          ],
          "datePublic": "2024-09-27T17:50:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,\u0026nbsp;HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to\u0026nbsp;cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.\u0026nbsp;"
                }
              ],
              "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,\u00a0HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to\u00a0cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-252",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-252 PHP Local File Inclusion"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-08T03:56:31.849Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-94p6-54jq-9mwp"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "cgi.force_redirect configuration is bypassable due to the environment variable collision",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-8927",
        "datePublished": "2024-10-08T03:56:31.849Z",
        "dateReserved": "2024-09-17T04:09:57.362Z",
        "dateUpdated": "2025-11-03T22:33:09.411Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-8926 (GCVE-0-2024-8926)

    Vulnerability from cvelistv5 – Published: 2024-10-08 03:48 – Updated: 2025-11-03 22:33
    VLAI
    Title
    PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)
    Summary
    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3  may still be bypassed and the same command injection related to Windows "Best Fit" codepage behavior can be achieved. This may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-08 12:55 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.30 (semver)
    Affected: 8.2.* , < 8.2.24 (semver)
    Affected: 8.3.* , < 8.3.12 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.30 (semver)
    Affected: 8.2.0 , < 8.2.24 (semver)
    Affected: 8.3.0 , < 8.3.12 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-27 17:50
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.30",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.24",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.12",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8926",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-08T12:55:27.311454Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-08T13:52:37.171Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:06.473Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20241101-0003/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "platforms": [
                "Windows"
              ],
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.30",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.24",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.12",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "https://github.com/MortalAndTry"
            }
          ],
          "datePublic": "2024-09-27T17:50:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ewhen using a certain non-standard configurations of Windows codepages, the fixes for\u0026nbsp;\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/advisories/GHSA-vxpp-6299-mxw3\"\u003eCVE-2024-4577\u003c/a\u003e\u0026nbsp;may still be bypassed and the same command injection related to Windows \"Best Fit\" codepage behavior can be achieved. This\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003emay allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.\u003c/span\u003e\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12,\u00a0when using a certain non-standard configurations of Windows codepages, the fixes for\u00a0 CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3 \u00a0may still be bypassed and the same command injection related to Windows \"Best Fit\" codepage behavior can be achieved. This\u00a0may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-24T21:12:33.554Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-p99j-rfp4-xqvq"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-p99j-rfp",
            "discovery": "EXTERNAL"
          },
          "title": "PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-8926",
        "datePublished": "2024-10-08T03:48:53.628Z",
        "dateReserved": "2024-09-17T04:06:56.550Z",
        "dateUpdated": "2025-11-03T22:33:06.473Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-8925 (GCVE-0-2024-8925)

    Vulnerability from cvelistv5 – Published: 2024-10-08 03:35 – Updated: 2025-11-03 22:33
    VLAI
    Title
    Erroneous parsing of multipart form data
    Summary
    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-08 12:56 UTC
    CWE
    • CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.30 (semver)
    Affected: 8.2.* , < 8.2.24 (semver)
    Affected: 8.3.* , < 8.3.12 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.30 (semver)
    Affected: 8.2.0 , < 8.2.24 (semver)
    Affected: 8.3.0 , < 8.3.12 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.30",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.24",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.12",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8925",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-08T12:56:50.614930Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-444",
                    "description": "CWE-444 Inconsistent Interpretation of HTTP Requests (\u0027HTTP Request/Response Smuggling\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-17T17:56:24.654Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:33:05.003Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://security.netapp.com/advisory/ntap-20241101-0003/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.30",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.24",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.12",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mihail Kirov"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIn PHP versions\u003cspan style=\"background-color: var(--wht);\"\u003e\u0026nbsp;8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, e\u003c/span\u003erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.\u0026nbsp;\u003c/p\u003e\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "In PHP versions\u00a08.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-153",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-153 Input Data Manipulation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-08T03:35:02.673Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Erroneous parsing of multipart form data",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-8925",
        "datePublished": "2024-10-08T03:35:02.673Z",
        "dateReserved": "2024-09-17T03:59:29.523Z",
        "dateUpdated": "2025-11-03T22:33:05.003Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-2408 (GCVE-0-2024-2408)

    Vulnerability from cvelistv5 – Published: 2024-06-09 19:55 – Updated: 2025-03-21 18:03
    VLAI
    Title
    PHP is vulnerable to the Marvin Attack
    Summary
    The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. PHP Windows builds for the versions 8.1.29, 8.2.20 and 8.3.8 and above include OpenSSL patches that fix the vulnerability.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-03-14 13:58 UTC
    CWE
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.29 (semver)
    Affected: 8.2.* , < 8.2.20 (semver)
    Affected: 8.3.* , < 8.3.8 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.29 (semver)
    Affected: 8.2.0 , < 8.2.20 (semver)
    Affected: 8.3.0 , < 8.3.8 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fedoraproject fedora Affected: 40
        cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-09 19:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.29",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.20",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.8",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fedora",
                "vendor": "fedoraproject",
                "versions": [
                  {
                    "status": "affected",
                    "version": "40"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.9,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2408",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-03-14T13:58:06.996571Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-203",
                    "description": "CWE-203 Observable Discrepancy",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-14T13:58:57.829Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-03-21T18:03:45.831Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
              },
              {
                "url": "https://security.netapp.com/advisory/ntap-20250321-0008/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "openssl"
              ],
              "product": "PHP",
              "programRoutines": [
                {
                  "name": "openssl_private_decrypt"
                }
              ],
              "repo": "https://github.com/php/php-src",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.29",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.20",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.8",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Hubert Kario"
            }
          ],
          "datePublic": "2024-06-09T19:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: var(--wht);\"\u003eThe openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/openssl/openssl/pull/13817\"\u003ehttps://github.com/openssl/openssl/pull/13817\u003c/a\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable.\u003cbr\u003e\u003cbr\u003e\u003c/span\u003ePHP Windows builds for the versions\u0026nbsp;8.1.29,\u0026nbsp;8.2.20 and\u0026nbsp;8.3.8 and above include OpenSSL patches that fix the vulnerability.\u0026nbsp;\u003cbr\u003e\u003cbr\u003e"
                }
              ],
              "value": "The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request:  https://github.com/openssl/openssl/pull/13817  (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable.\n\nPHP Windows builds for the versions\u00a08.1.29,\u00a08.2.20 and\u00a08.3.8 and above include OpenSSL patches that fix the vulnerability."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-13T04:06:08.508Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use a recent patched version of OpenSSL.\u0026nbsp;"
                }
              ],
              "value": "Use a recent patched version of OpenSSL."
            }
          ],
          "source": {
            "advisory": "GHSA-hh26-4ppw-5864",
            "discovery": "UNKNOWN"
          },
          "title": "PHP is vulnerable to the Marvin Attack",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-2408",
        "datePublished": "2024-06-09T19:55:51.625Z",
        "dateReserved": "2024-03-12T21:18:50.326Z",
        "dateUpdated": "2025-03-21T18:03:45.831Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5585 (GCVE-0-2024-5585)

    Vulnerability from cvelistv5 – Published: 2024-06-09 18:36 – Updated: 2025-02-13 17:54
    VLAI
    Title
    Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
    Summary
    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-16 17:52 UTC
    CWE
    • CWE-116 - Improper Encoding or Escaping of Output
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.29 (semver)
    Affected: 8.2.* , < 8.2.20 (semver)
    Affected: 8.3.* , < 8.3.8 (semver)
    Create a notification for this product.
    php php Affected: 8.1.0 , < 8.1.29 (semver)
        cpe:2.3:a:php:php:8.1.0:-:*:*:*:*:*:*
    Create a notification for this product.
    php php Affected: 8.2.0 , < 8.2.20 (semver)
        cpe:2.3:a:php:php:8.2.0:-:*:*:*:*:*:*
    Create a notification for this product.
    php php Affected: 8.3.0 , < 8.3.8 (semver)
        cpe:2.3:a:php:php:8.3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-09 18:30
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:8.1.0:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.1.29",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:php:php:8.2.0:-:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.2.20",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:php:php:8.3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThan": "8.3.8",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5585",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-16T17:52:45.720953Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-16T18:15:25.949Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-19T07:35:25.799Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/php/php-src/security/advisories/GHSA-9fcc-425m-g385"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/06/07/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240726-0002/"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/command-injection-vulnerability-in-php-on-windows-systems-cve-2024-1874-and-cve-2024-5585"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "proc_open"
              ],
              "platforms": [
                "Windows"
              ],
              "product": "PHP",
              "repo": "https://github.com/php/php-src",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.29",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.20",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.8",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This problem only present in Windows versions of PHP. \u003cbr\u003e"
                }
              ],
              "value": "This problem only present in Windows versions of PHP."
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "tianstcht"
            }
          ],
          "datePublic": "2024-06-09T18:30:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP versions\u003cspan style=\"background-color: var(--wht);\"\u003e\u0026nbsp;8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for\u0026nbsp;\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eCVE-2024-1874 does not work if the command name includes trailing spaces. Original issue:\u0026nbsp;\u003c/span\u003ewhen using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e\u003cbr\u003e\u003c/span\u003e"
                }
              ],
              "value": "In PHP versions\u00a08.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for\u00a0CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue:\u00a0when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-116",
                  "description": "CWE-116 Improper Encoding or Escaping of Output",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-28T14:06:03.143Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-9fcc-425m-g385"
            },
            {
              "url": "http://www.openwall.com/lists/oss-security/2024/06/07/1"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240726-0002/"
            }
          ],
          "source": {
            "advisory": "GHSA-9fcc-425m-g385",
            "discovery": "EXTERNAL"
          },
          "title": "Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Using proc_open() string syntax avoids the problem. \u003cbr\u003e"
                }
              ],
              "value": "Using proc_open() string syntax avoids the problem."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-5585",
        "datePublished": "2024-06-09T18:36:50.477Z",
        "dateReserved": "2024-06-01T00:08:21.997Z",
        "dateUpdated": "2025-02-13T17:54:21.435Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5458 (GCVE-0-2024-5458)

    Vulnerability from cvelistv5 – Published: 2024-06-09 18:26 – Updated: 2025-11-03 22:32
    VLAI
    Title
    Filter bypass in filter_var (FILTER_VALIDATE_URL)
    Summary
    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-10 19:55 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.29 (semver)
    Affected: 8.2.* , < 8.2.20 (semver)
    Affected: 8.3.* , < 8.3.8 (semver)
    Create a notification for this product.
    php php Affected: 7.3.27 , ≤ 7.3.33 (semver)
    Affected: 7.4.15 , ≤ 7.4.33 (semver)
    Affected: 8.0.2 , ≤ 8.0.30 (semver)
    Affected: 8.1.0 , < 8.1.29 (semver)
    Affected: 8.2.0 , < 8.2.20 (semver)
    Affected: 8.3.0 , < 8.3.8 (semver)
        cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fedoraproject fedora Affected: 40
        cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-09 18:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "php",
                "vendor": "php",
                "versions": [
                  {
                    "lessThanOrEqual": "7.3.33",
                    "status": "affected",
                    "version": "7.3.27",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.4.33",
                    "status": "affected",
                    "version": "7.4.15",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "8.0.30",
                    "status": "affected",
                    "version": "8.0.2",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.1.29",
                    "status": "affected",
                    "version": "8.1.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.2.20",
                    "status": "affected",
                    "version": "8.2.0",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "8.3.8",
                    "status": "affected",
                    "version": "8.3.0",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fedora",
                "vendor": "fedoraproject",
                "versions": [
                  {
                    "status": "affected",
                    "version": "40"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5458",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-10T19:55:47.057816Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-345",
                    "description": "CWE-345 Insufficient Verification of Data Authenticity",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-14T14:13:20.514Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T22:32:24.445Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/06/07/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240726-0001/"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "filter"
              ],
              "product": "PHP",
              "programFiles": [
                "ext/filter/logical_filters.c"
              ],
              "repo": "https://github.com/php/php-src",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.29",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.20",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.8",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "c01l"
            }
          ],
          "datePublic": "2024-06-09T18:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In PHP versions\u003cspan style=\"background-color: var(--wht);\"\u003e\u0026nbsp;8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e(FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: var(--wht);\"\u003e\u003cbr\u003e\u003cbr\u003e\u003c/span\u003e"
                }
              ],
              "value": "In PHP versions\u00a08.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs\u00a0(FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-28T14:05:58.895Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w"
            },
            {
              "url": "http://www.openwall.com/lists/oss-security/2024/06/07/1"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"
            },
            {
              "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"
            },
            {
              "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240726-0001/"
            }
          ],
          "source": {
            "advisory": "GHSA-w8qr-v226-r27w",
            "discovery": "EXTERNAL"
          },
          "title": "Filter bypass in filter_var (FILTER_VALIDATE_URL)",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-5458",
        "datePublished": "2024-06-09T18:26:28.804Z",
        "dateReserved": "2024-05-29T00:23:37.703Z",
        "dateUpdated": "2025-11-03T22:32:24.445Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-2756 (GCVE-0-2024-2756)

    Vulnerability from cvelistv5 – Published: 2024-04-29 03:34 – Updated: 2025-11-04 17:18
    VLAI
    Title
    __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix
    Summary
    Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-29 17:19 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Assigner
    Impacted products
    Vendor Product Version
    PHP Group PHP Affected: 8.1.* , < 8.1.28 (semver)
    Affected: 8.2.* , < 8.2.18 (semver)
    Affected: 8.3.* , < 8.3.5 (semver)
    Create a notification for this product.
    php archive_tar Affected: *
        cpe:2.3:a:php:archive_tar:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-04-11 17:12
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:archive_tar:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "archive_tar",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "*"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2756",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-29T17:19:19.916680Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:30:06.555Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:18:00.434Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5j-x4v4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/04/12/11"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240510-0008/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "PHP",
              "vendor": "PHP Group",
              "versions": [
                {
                  "lessThan": "8.1.28",
                  "status": "affected",
                  "version": "8.1.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.18",
                  "status": "affected",
                  "version": "8.2.*",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.3.5",
                  "status": "affected",
                  "version": "8.3.*",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Marco Squarcina"
            }
          ],
          "datePublic": "2024-04-11T17:12:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eDue to an incomplete fix to \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/advisories/GHSA-c43m-486j-j32p\"\u003eCVE-2022-31629\u003c/a\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e, network and same-site attackers can set a standard insecure cookie in the victim\u0027s browser which is treated as a \u003c/span\u003e\u003ccode\u003e__Host-\u003c/code\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;or \u003c/span\u003e\u003ccode\u003e__Secure-\u003c/code\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;cookie by PHP applications.\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "Due to an incomplete fix to  CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim\u0027s browser which is treated as a __Host-\u00a0or __Secure-\u00a0cookie by PHP applications."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T17:11:03.733Z",
            "orgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
            "shortName": "php"
          },
          "references": [
            {
              "url": "https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5j-x4v4"
            },
            {
              "url": "http://www.openwall.com/lists/oss-security/2024/04/12/11"
            },
            {
              "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240510-0008/"
            }
          ],
          "source": {
            "advisory": "https://github.com/php/php-src/security/advisories/GHSA-wpj3-hf5",
            "discovery": "EXTERNAL"
          },
          "title": "__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dd77f84a-d19a-4638-8c3d-a322d820ed2b",
        "assignerShortName": "php",
        "cveId": "CVE-2024-2756",
        "datePublished": "2024-04-29T03:34:16.912Z",
        "dateReserved": "2024-03-21T05:10:24.594Z",
        "dateUpdated": "2025-11-04T17:18:00.434Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-41504 (GCVE-0-2023-41504)

    Vulnerability from cvelistv5 – Published: 2024-03-13 00:00 – Updated: 2024-08-05 13:49
    VLAI
    Summary
    SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-05 13:47 UTC
    CWE
    • n/a
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    php student_enrollment Affected: 1.0
        cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:01:35.318Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/ASR511-OO7/CVE-2023-41504/blob/main/CVE-25"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "student_enrollment",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-41504",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-05T13:47:48.095937Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-89",
                    "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:49:34.427Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-13T20:34:34.580Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/ASR511-OO7/CVE-2023-41504/blob/main/CVE-25"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-41504",
        "datePublished": "2024-03-13T00:00:00.000Z",
        "dateReserved": "2023-08-30T00:00:00.000Z",
        "dateUpdated": "2024-08-05T13:49:34.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-41503 (GCVE-0-2023-41503)

    Vulnerability from cvelistv5 – Published: 2024-03-07 00:00 – Updated: 2025-04-16 15:53
    VLAI
    Summary
    Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-07 16:45 UTC
    CWE
    • n/a
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Impacted products
    Vendor Product Version
    php student_enrollment Affected: v1.0
        cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "student_enrollment",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "v1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-41503",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-07T16:45:01.909539Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-94",
                    "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-16T15:53:50.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:01:35.312Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/ASR511-OO7/CVE-2023-41503/blob/main/CVE-26"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-07T08:55:53.343Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/ASR511-OO7/CVE-2023-41503/blob/main/CVE-26"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-41503",
        "datePublished": "2024-03-07T00:00:00.000Z",
        "dateReserved": "2023-08-30T00:00:00.000Z",
        "dateUpdated": "2025-04-16T15:53:50.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-41506 (GCVE-0-2023-41506)

    Vulnerability from cvelistv5 – Published: 2024-02-27 00:00 – Updated: 2024-08-27 19:14
    VLAI
    Summary
    An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-02-27 20:04 UTC
    CWE
    • n/a
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Impacted products
    Vendor Product Version
    php student_enrollment Affected: v1.0
        cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:01:35.219Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/ASR511-OO7/CVE-2023-41506/blob/main/CVE-23"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:php:student_enrollment:v1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "student_enrollment",
                "vendor": "php",
                "versions": [
                  {
                    "status": "affected",
                    "version": "v1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-41506",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-27T20:04:34.246116Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-434",
                    "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-27T19:14:44.291Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An arbitrary file upload vulnerability in the Update/Edit Student\u0027s Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-27T01:20:21.645Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/ASR511-OO7/CVE-2023-41506/blob/main/CVE-23"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2023-41506",
        "datePublished": "2024-02-27T00:00:00.000Z",
        "dateReserved": "2023-08-30T00:00:00.000Z",
        "dateUpdated": "2024-08-27T19:14:44.291Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }