CVE-2018-5712
high-risk
Published 2018-01-16
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
Do I need to act?
!
89.2% chance of exploitation in next 30 days
EPSS score — higher than 11% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10
Medium
NETWORK
/ LOW complexity
Affected Products (7)
References (26)
Release Notes
http://php.net/ChangeLog-5.php
Release Notes
http://php.net/ChangeLog-7.php
Third Party Advisory
http://www.securityfocus.com/bid/102742
Third Party Advisory
http://www.securityfocus.com/bid/104020
Third Party Advisory
http://www.securitytracker.com/id/1040363
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1296
Issue Tracking
https://bugs.php.net/bug.php?id=74782
Third Party Advisory
https://usn.ubuntu.com/3566-1/
Third Party Advisory
https://usn.ubuntu.com/3600-1/
Third Party Advisory
https://usn.ubuntu.com/3600-2/
Release Notes
http://php.net/ChangeLog-5.php
Release Notes
http://php.net/ChangeLog-7.php
Third Party Advisory
http://www.securityfocus.com/bid/102742
Third Party Advisory
http://www.securityfocus.com/bid/104020
Third Party Advisory
http://www.securitytracker.com/id/1040363
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1296
and 6 more references
57
/ 100
high-risk
Severity
23/34 · High
Exploitability
20/34 · Moderate
Exposure
14/34 · Moderate