CVE-2024-8925

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Mar 17, 2025
CWE ID 444

Summary

CVE-2024-8925 is a vulnerability affecting PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12. This issue stems from incorrect handling of multipart form data in HTTP POST requests. A malicious attacker can exploit this vulnerability by manipulating submitted data, potentially excluding legitimate data from processing. This could result in erroneous application behavior and, in some cases, allow the attacker to exert control over the submitted data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHP: Hypertext Preprocessor

Affected Vendors

  • Php