CVE-2018-10547: XSS
An issue was discovered in ext/phar/pharobject.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-5712.
Other sources
Fixed bug (fix for CVE-2018-5712 may not be complete). (CVE-2018-10547)
— PHP
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-10547?
CVE-2018-10547 has a medium severity rating due to the potential for reflected XSS attacks.
How do I fix CVE-2018-10547?
To fix CVE-2018-10547, upgrade to PHP versions 5.6.36, 7.0.30, 7.1.17, or 7.2.5 or later.
Which versions of PHP are affected by CVE-2018-10547?
CVE-2018-10547 affects PHP versions before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5.
What type of vulnerability is CVE-2018-10547?
CVE-2018-10547 is categorized as a reflected cross-site scripting (XSS) vulnerability.
Is CVE-2018-10547 a critical vulnerability?
CVE-2018-10547 is not categorized as critical, but it poses risks that should be addressed promptly.