CVE-2024-8926
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 78
Summary
CVE-2024-8926 is a new vulnerability affecting PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12. This issue arises when using specific non-standard configurations of Windows codepages. Although patches for CVE-2024-4577 were released, they may not entirely address this problem. With this vulnerability, a malicious user can inject commands to the PHP binary being run. As a result, they may gain access to the source code of scripts or execute arbitrary PHP code on the server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PHP: Hypertext Preprocessor
Affected Vendors
- Php