Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8925

Опубликовано: 08 окт. 2024
Источник: nvd
CVSS3: 3.1
CVSS3: 5.3
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php-fpm:php-fpm:*:*:*:*:*:*:*:*
Версия от 8.1.0 (включая) до 8.1.30 (исключая)
cpe:2.3:a:php-fpm:php-fpm:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 8.2.24 (исключая)
cpe:2.3:a:php-fpm:php-fpm:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.12 (исключая)

EPSS

Процентиль: 11%
0.00038
Низкий

3.1 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-444

Связанные уязвимости

CVSS3: 3.1
ubuntu
8 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
redhat
9 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

CVSS3: 5.3
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 3.1
debian
8 месяцев назад

In PHP versions8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ...

CVSS3: 3.1
github
9 месяцев назад

Erroneous parsing of multipart form data

EPSS

Процентиль: 11%
0.00038
Низкий

3.1 Low

CVSS3

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-444