CVE-2024-8925
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Oct 8, 2024
Updated: Mar 17, 2025
CWE ID 444
Summary
CVE-2024-8925 is a vulnerability affecting PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12. This issue stems from incorrect handling of multipart form data in HTTP POST requests. A malicious attacker can exploit this vulnerability by manipulating submitted data, potentially excluding legitimate data from processing. This could result in erroneous application behavior and, in some cases, allow the attacker to exert control over the submitted data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PHP: Hypertext Preprocessor
Affected Vendors
- Php