Vulnerability Description
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | <= 5.6.32 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://php.net/ChangeLog-7.phpRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/102742Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/104020Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040363Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1296Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519
- https://bugs.php.net/bug.php?id=74782Issue TrackingPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00025.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3566-1/Third Party Advisory
- https://usn.ubuntu.com/3600-1/Third Party Advisory
- https://usn.ubuntu.com/3600-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://php.net/ChangeLog-5.phpRelease NotesVendor Advisory
- http://php.net/ChangeLog-7.phpRelease NotesVendor Advisory
FAQ
What is CVE-2018-5712?
CVE-2018-5712 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar f...
How severe is CVE-2018-5712?
CVE-2018-5712 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5712?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php, Debian Debian Linux, Canonical Ubuntu Linux.