CVE-2021-30134

MEDIUM NUCLEI

php-mod/curl <2.3.2 - XSS

Title source: llm

Description

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

Nuclei Templates (1)

Php-mod/curl Library <2.3.2 - Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat

Scores

CVSS v3 6.1
EPSS 0.0324
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (7)
ht_slider_range_for_amazon_affiliates_project/ht_slider_range_for_amazon_affiliates < 1.1.6
php_curl_class_project/php_curl_class < 2.3.2
php-mod/curl 0 - 2.3.2Packagist
ptwooplugins/invoicing_with_invoicexpress_for_woocommerce < 3.0.3
qiwi/woo-qiwi-payment-gateway < 0.0.9
shopello_api_project/shopello_api < 2.9.0
teamleade/teamleader_crm_forms < 2.1.0
Published Dec 26, 2022
Tracked Since Feb 18, 2026