Skip to content

XML-RPC for PHP's debugger vulnerable to possible XSS attack

Moderate severity GitHub Reviewed Published Jan 11, 2023 in gggeek/phpxmlrpc • Updated Jan 11, 2023

Package

composer phpxmlrpc/phpxmlrpc (Composer)

Affected versions

< 4.9.2

Patched versions

4.9.2

Description

The bundled xml-rpc debugger is susceptible to XSS attacks.

Since the debugger is not designed to be exposed to end users but only to the developers using this library, and in the default configuration it is not exposed to requests from the web, the likelihood of exploitation may be low.

References

@gggeek gggeek published to gggeek/phpxmlrpc Jan 11, 2023
Published to the GitHub Advisory Database Jan 11, 2023
Reviewed Jan 11, 2023
Last updated Jan 11, 2023

Severity

Moderate

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-pxqj-xrv5-qvjf

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.