Skip to content

XSS attack possible in the debugger

Low
gggeek published GHSA-pxqj-xrv5-qvjf Jan 11, 2023

Package

composer phpxmlrpc/phpxmlrpc (Composer)

Affected versions

< 4.9.2

Patched versions

4.9.2

Description

The bundled xml-rpc debugger is susceptible to XSS attacks.

Since the debugger is not designed to be exposed to end users but only to the developers using this library, and in the default configuration it is not exposed to requests from the web, the severity of this issue can be considered low.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs