SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-8925

This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

MEDIUM 5.3EPSS 0.94%

Does this matter?

Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.

Description

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.94% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
php/php
Source
security@php.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.