Record summary

CVE-2021-30134 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.3.2 · Fixed in 2.3.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPhp-mod/curl Library <2.3.2 - Cross-Site ScriptingCVSS 6.1

Php-mod/curl library before 2.3.2 contains a cross-site scripting vulnerability via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. An attacker can inject arbitrary script, which can allow theft of cookie-based authentication credentials and launch of other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

Upgrade to Php-mod/curl Library version 2.3.2 or later to mitigate the vulnerability.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2021cvexssphp-modwpscanphp_curl_class_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:php_curl_class_project:php_curl_class:*:*:*:*:*:*:*:*
Google: inurl:"/php-curl-test/post_file_path_upload.php"

Source: ProjectDiscovery

References

4