CVE-2024-5458

MEDIUM

Php < 7.3.33 - Data Authenticity Bypass

Title source: rule
STIX 2.1

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

Scores

CVSS v3 5.3
EPSS 0.0358
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (2)
fedoraproject/fedora 40
php/php 7.3.27 - 7.3.33
Published Jun 09, 2024
Tracked Since Feb 18, 2026