cbcvebase.
CVE-2024-8925
published 2024-10-08

CVE-2024-8925: In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianphp7.4< php7.4 7.4.33-1+deb11u6 (bullseye)php7.4 7.4.33-1+deb11u6 (bullseye)
debianphp8.2< php7.4 7.4.33-1+deb11u6 (bullseye)php7.4 7.4.33-1+deb11u6 (bullseye)
msrcazl3_php_8.3.12-1_on_azure_linux_3.0
msrcazl3_php_8.3.8-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_php_8.1.29-1_on_cbl_mariner_2.0
msrccbl2_php_8.1.30-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
phpphp>= 8.1.0 < 8.1.308.1.30
phpphp>= 8.2.0 < 8.2.248.2.24
phpphp>= 8.3.0 < 8.3.128.3.12
php5php5>= 0 < 5.5.9+dfsg-1ubuntu4.29+esm165.5.9+dfsg-1ubuntu4.29+esm16
php_groupphp>= 8.1.* < 8.1.308.1.30
php_groupphp>= 8.2.* < 8.2.248.2.24
php_groupphp>= 8.3.* < 8.3.128.3.12

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM