VulnerabilityModified
CVE-2018-5712
There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
MEDIUM 6.1EPSS 79.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 79.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 79.95% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- php/php · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://php.net/ChangeLog-7.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/102742Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104020Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040363Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=74782Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00025.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3566-1/Third Party Advisory
- https://usn.ubuntu.com/3600-1/Third Party Advisory
- https://usn.ubuntu.com/3600-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://php.net/ChangeLog-5.phpRelease Notes, Vendor Advisory
- http://php.net/ChangeLog-7.phpRelease Notes, Vendor Advisory
- http://www.securityfocus.com/bid/102742Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104020Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040363Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=74782Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00025.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3566-1/Third Party Advisory
- https://usn.ubuntu.com/3600-1/Third Party Advisory
- https://usn.ubuntu.com/3600-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.