CVE-2024-8926

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 16, 2024
CWE ID 78

Summary

CVE-2024-8926 is a new vulnerability affecting PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12. This issue arises when using specific non-standard configurations of Windows codepages. Although patches for CVE-2024-4577 were released, they may not entirely address this problem. With this vulnerability, a malicious user can inject commands to the PHP binary being run. As a result, they may gain access to the source code of scripts or execute arbitrary PHP code on the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHP: Hypertext Preprocessor

Affected Vendors

  • Php