CVE-2025-43717CWE-531
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php…
Medium · published April 17, 2025
What it is
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.
The record
Technical detail
- CVSS v3.1
- 5.4 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00315 · 24.1th percentile
- Weakness
- CWE-531 · Inclusion of Sensitive Information in Test Code
- Published
- 2025-04-17T00:00Z
EPSS history
Timeline