vulnerability

CentOS Linux: CVE-2018-10547: Moderate: php security update (CESA-2020:1112)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Apr 29, 2018
Added
Apr 1, 2020
Modified
May 25, 2023

Description

An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-5712.

Solution(s)

centos-upgrade-phpcentos-upgrade-php-bcmathcentos-upgrade-php-clicentos-upgrade-php-commoncentos-upgrade-php-dbacentos-upgrade-php-debuginfocentos-upgrade-php-develcentos-upgrade-php-embeddedcentos-upgrade-php-enchantcentos-upgrade-php-fpmcentos-upgrade-php-gdcentos-upgrade-php-intlcentos-upgrade-php-ldapcentos-upgrade-php-mbstringcentos-upgrade-php-mysqlcentos-upgrade-php-mysqlndcentos-upgrade-php-odbccentos-upgrade-php-pdocentos-upgrade-php-pgsqlcentos-upgrade-php-processcentos-upgrade-php-pspellcentos-upgrade-php-recodecentos-upgrade-php-snmpcentos-upgrade-php-soapcentos-upgrade-php-xmlcentos-upgrade-php-xmlrpc
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.