QID 379241

Date Published: 2024-02-05

QID 379241: XAMPP Insecure Permission Vulnerability (CVE-2022-29376)

XAMPP is an Apache distribution designed for easy installation. It includes MySQL, PHP and Perl CGI support.

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

Affected Version:
1- Older versions upto to 8.1.4
Detection Logic:
It checks for vulnerable version of XAMPP by checking the file version on Microsoft Windows.

If this vulnerability is successfully exploited then an attacker can execute arbitrary code via overwriting binaries located in the directory.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Update to Version 8.2.12, 8.1.25 and 8.0.30 to resolve this issue. The latest version is available for download fromXAMPP Web site.For More Information Kindly check Reference

    CVEs related to QID 379241

    Software Advisories
    Advisory ID Software Component Link
    new_xampp_20231119 URL Logo www.apachefriends.org/blog/new_xampp_20231119.html