CVE-2025-43717
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-43717 is a vulnerability affecting PEAR HTTP_Request2 before version 2.7.0. The issue lies in multiple files in the tests directory, specifically tests/_network/getparameters.php and tests/_network/postparameters.php. These files can reflect any GET or POST parameters, leading to Cross-Site Scripting (XSS) attacks. Attackers can exploit this vulnerability by injecting malicious scripts, posing a significant security risk to applications using these affected PEAR components. It is strongly recommended to update PEAR HTTP_Request2 to version 2.7.0 or later to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.