CVE-2025-43717CWE-531

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php…

Medium · published April 17, 2025

CVSS v3.1
5.4
EPSS
0%
Percentile
24.1
In the wild
Unconfirmed
What it is

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00315 · 24.1th percentile
Weakness
CWE-531 · Inclusion of Sensitive Information in Test Code
Published
2025-04-17T00:00Z
EPSS history
Timeline
  • 17 APR 00:00Z
    In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php…
    cvelistv5