GHSA-pxqj-xrv5-qvjf

Suggest an improvement
Source
https://github.com/advisories/GHSA-pxqj-xrv5-qvjf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-pxqj-xrv5-qvjf/GHSA-pxqj-xrv5-qvjf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pxqj-xrv5-qvjf
Published
2023-01-11T23:51:00Z
Modified
2024-11-28T05:38:57Z
Summary
XML-RPC for PHP's debugger vulnerable to possible XSS attack
Details

The bundled xml-rpc debugger is susceptible to XSS attacks.

Since the debugger is not designed to be exposed to end users but only to the developers using this library, and in the default configuration it is not exposed to requests from the web, the likelihood of exploitation may be low.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-01-11T23:51:00Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / phpxmlrpc/phpxmlrpc

Package

Name
phpxmlrpc/phpxmlrpc
Purl
pkg:composer/phpxmlrpc/phpxmlrpc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.9.2

Affected versions

3.*
3.0.0
3.0.1
3.1.0
3.1.1
3.1.2
4.*
4.0.0-alpha
4.0.0
4.0.1
4.1.0
4.1.1
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.7.2
4.8.0
4.8.1
4.9.0
4.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-pxqj-xrv5-qvjf/GHSA-pxqj-xrv5-qvjf.json"