CVE-2021-30134
published 2022-12-26CVE-2021-30134: php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to…
PriorityP334medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
1.26%
66.0th percentile
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ht_slider_range_for_amazon_affiliates_project | ht_slider_range_for_amazon_affiliates | < 1.1.6 | 1.1.6 |
| php-mod | curl | >= 0 < 2.3.2 | 2.3.2 |
| php_curl_class_project | php_curl_class | < 2.3.2 | 2.3.2 |
| ptwooplugins | invoicing_with_invoicexpress_for_woocommerce | < 3.0.3 | 3.0.3 |
| qiwi | woo-qiwi-payment-gateway | <= 0.0.9 | — |
| shopello_api_project | shopello_api | <= 2.9.0 | — |
| teamleade | teamleader_crm_forms | < 2.1.0 | 2.1.0 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
php-mod/curl allows Cross-site Scripting
osv·2022-12-26
CVE-2021-30134 [MEDIUM] php-mod/curl allows Cross-site Scripting
php-mod/curl allows Cross-site Scripting
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the `post_file_path_upload.php` key parameter and the POST data to `post_multidimensional.php`.
GHSA
php-mod/curl allows Cross-site Scripting
ghsa·2022-12-26
CVE-2021-30134 [MEDIUM] CWE-79 php-mod/curl allows Cross-site Scripting
php-mod/curl allows Cross-site Scripting
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the `post_file_path_upload.php` key parameter and the POST data to `post_multidimensional.php`.
No detection rules found.
Nuclei
Php-mod/curl Library <2.3.2 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2021-30134 [MEDIUM] Php-mod/curl Library <2.3.2 - Cross-Site Scripting
Php-mod/curl Library "
matchers-condition: and
matchers:
- type: word
words:
- 'key":""'
- type: word
part: header
words:
- text/html
- type: status
status:
- 200
# digest: 490a0046304402207247b4ba7b6c97cdd4eb7134252ea1780f5fcc7f8d138513d09842dcf17baef3022004fa3bdc805e72bf95cdcce0c629ec9cc2626b6c6a5558560c807af95e4cd077:922c64590222798bb761d5b6d8e72950
2022-12-26
Published