ALPINE-CVE-2018-5712 PUBLISHED CVSS 6.099999904632568 MEDIUM

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.4php50, 5.2.10-r0, 5.2.10-r2
Alpine:v3.5php50, 5.2.10-r0, 5.2.10-r2

Timeline

References

Open in Interactive Console →