CVE-2024-8927
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-8927 is a vulnerability affecting PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, and 8.3.* before 8.3.12. In these versions, the HTTP_REDIRECT_STATUS variable, used to check if a CGI binary is being run by the HTTP server, can be manipulated by the request submitter through HTTP headers. This can cause the cgi.force_redirect option to malfunction, potentially leading to arbitrary file inclusion in PHP. The vulnerability may allow attackers to gain unauthorized access to sensitive information or execute malicious code. Users are advised to update their PHP installations as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PHP: Hypertext Preprocessor
Affected Vendors
- Php