Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17543

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

A flaw was found in PHP. Improper escaping of backslashes in attacker-provided parameters can lead to a SQL injection vulnerability. A remote attacker could exploit this flaw by crafting malicious input, potentially gaining unauthorized access to sensitive information, manipulating data, or causing a denial of service.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important. A remote attacker could exploit this flaw to inject malicious SQL commands into a connected PostgreSQL database, potentially exposing or manipulating sensitive data. However, only applications using PHP's older pg_insert(), pg_update(), pg_select(), or pg_delete() functions with unsanitized user input are at risk applications built on modern practices such as PDO, prepared statements, or parameterized queries are not affected. The vulnerability stems from improper handling of backslash characters in PHP's PostgreSQL extension, which can allow an attacker to break out of expected query boundaries and execute unintended SQL commands.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10phpAffected
Red Hat Enterprise Linux 10php8.4Affected
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.4/phpAffected
Red Hat Enterprise Linux 8php:8.2/phpAffected
Red Hat Enterprise Linux 9phpAffected
Red Hat Enterprise Linux 9php:8.2/phpAffected
Red Hat Enterprise Linux 9php:8.3/phpAffected
Red Hat Hardened Imagesphp-main-8.5.9-1.hum1FixedRHSA-2026:4720028.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2509254php: ext-pgsql: PHP: SQL injection via improper backslash escaping

EPSS

Процентиль: 38%
0.00468
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 дней назад

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
nvd
12 дней назад

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
msrc
4 дня назад

SQL injection in ext-pgsql via E'...' backslash breakout

CVSS3: 9.8
debian
12 дней назад

Improper escaping of backslashes in attacker-provided parameters would ...

github
12 дней назад

SQL injection in ext-pgsql via E'...' backslash breakout

EPSS

Процентиль: 38%
0.00468
Низкий

7.4 High

CVSS3