CVE-2025-43717

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 17, 2025
CWE ID 531

Summary

CVE-2025-43717 is a vulnerability affecting PEAR HTTP_Request2 before version 2.7.0. The issue lies in multiple files in the tests directory, specifically tests/_network/getparameters.php and tests/_network/postparameters.php. These files can reflect any GET or POST parameters, leading to Cross-Site Scripting (XSS) attacks. Attackers can exploit this vulnerability by injecting malicious scripts, posing a significant security risk to applications using these affected PEAR components. It is strongly recommended to update PEAR HTTP_Request2 to version 2.7.0 or later to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share