QID 38910

Date Published: 2023-10-04

QID 38910: Hypertext Preprocessor (PHP) Multiple Vulnerabilities

PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications.

Affected Versions:
PHP versions from 8.0.0 prior to 8.0.30
PHP versions from 8.1.0 prior to 8.1.22
PHP versions from 8.2.0 prior to 8.2.8

QID Detection Logic (Unauthenticated):
This QID checks the HTTP Server header to see if the server is running a vulnerable version of PHP.

Successful exploitation of these vulnerabilities could allow an attacker to trigger stack buffer overflow or disclosure of any local files accessible to PHP.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to the latest version of PHP.

    CVEs related to QID 38910

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3qrf-m4j2-pcrr URL Logo github.com/php/php-src/security/advisories/GHSA-3qrf-m4j2-pcrr
    GHSA-jqcx-ccgc-xwhv URL Logo github.com/php/php-src/security/advisories/GHSA-jqcx-ccgc-xwhv