QID 38870

Date Published: 2022-06-01

QID 38870: Hypertext Preprocessor (PHP) Privilege Escalation Vulnerability

PHP is a general purpose scripting language that is especially suited for web development and can be embedded into HTML.

Affected Versions:
PHP 7.3 prior to version 7.3.32
PHP 7.4 prior to version 7.4.25
PHP 8.0 prior to version 8.0.12

QID Detection Logic
The qid checks the php version via banner.

A successful exploit may cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Customers are advised to upgrade to the latest version 7.4.25,8.0.12 .
    Vendor References

    CVEs related to QID 38870

    Software Advisories
    Advisory ID Software Component Link
    81026 URL Logo bugs.php.net/bug.php?id=81026