CVE-2021-30134
MEDIUM NUCLEIphp-mod/curl < 2.3.2 - Cross-Site Scripting via post_file_path_upload.php Key Parameter
Title source: llmExploitation Summary
CVE-2021-30134 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
Nuclei Templates (1)
Php-mod/curl Library <2.3.2 - Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://wpscan.com/vulnerability/0b547728-27d2-402e-ae17-90d539344ec7
Scores
CVSS v3
6.1
EPSS
0.0126
EPSS Percentile
65.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (7)
ht_slider_range_for_amazon_affiliates_project/ht_slider_range_for_amazon_affiliates
< 1.1.6
php-mod/curl
0 - 2.3.2Packagist
php_curl_class_project/php_curl_class
< 2.3.2
ptwooplugins/invoicing_with_invoicexpress_for_woocommerce
< 3.0.3
qiwi/woo-qiwi-payment-gateway
< 0.0.9
shopello_api_project/shopello_api
< 2.9.0
teamleade/teamleader_crm_forms
< 2.1.0
Published
Dec 26, 2022
Tracked Since
Feb 18, 2026