CVE-2021-37704
Exposed phpinfo() in PhpFastCache
Record summary
CVE-2021-37704 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
phpfastcacheBrowse PHPSocialNetwork / phpfastcache | CVE List | < 6.1.5 | affected |
| >= 7.0.0, < 7.1.2 | affected | ||
| >= 8.0.0, < 8.0.7 | affected | ||
phpfastcache/phpfastcacheBrowse Packagist / phpfastcache/phpfastcache | GitHub Advisory | Before 6.1.5 · Fixed in 6.1.5 | affected |
| 7.0.0 to < 7.1.2 · Fixed in 7.1.2 | affected | ||
| 8.0.0 to < 8.0.7 · Fixed in 8.0.7 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMphpfastcache - phpinfo Resource ExposureCVSS 4.3
phpinfo() is susceptible to resource exposure in unprotected composer vendor folders via phpfastcache/phpfastcache.
Impact
An attacker can gain access to sensitive information, such as server configuration details, PHP version, and installed extensions.
Remediation
Remove or restrict access to the phpinfo.php file in the phpfastcache library.
Source: ProjectDiscovery