CVE-2018-5712: XSS

Published Jun 19, 2017
·
Updated

A flaw was found in php when creating a .phar file and configuring apache to handle phar files using php, when accessing invalid page the page name is reflected back to the user in the 404 response. This user input is not being sanitized and therefore it is vulnerable to a reflected XSS. Making, every site configured to run .phar files using php vulnerable.

References: https://bugs.php.net/bug.php?id=74782 https://bugs.php.net/bug.php?id=74782

Patch: https://gist.github.com/anonymous/70d2f6bac8db576d6386bd79c1e6e081

Other sources

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1 ...

Debian

Fixed bug (fix for CVE-2018-5712 may not be complete). (CVE-2018-10547)

PHP

Affected Software

20 affected componentsFixes available
redhat/php<0:5.4.16-48.el7
0:5.4.16-48.el7
redhat/rh-php70-php<0:7.0.27-1.el6
0:7.0.27-1.el6
redhat/rh-php70-php<0:7.0.27-1.el7
0:7.0.27-1.el7
redhat/rh-php71-php<0:7.1.30-1.el7
0:7.1.30-1.el7
redhat/php<7.0.27
7.0.27
redhat/php<7.1.13
7.1.13
redhat/php<7.2.1
7.2.1
debian/php5
debian/php7.0
debian/php7.1
PHP PHP<7.0.30
7.0.30
PHP PHP<=5.6.32
PHP PHP>=7.0.0<=7.0.26
PHP PHP>7.1.0<=7.1.12
PHP PHP=7.2.0
Debian Debian Linux=7.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/php to a version that resolves this vulnerability.

    Fixed in 0:5.4.16-48.el7
  2. Upgrade

    Upgrade redhat/rh-php70-php to a version that resolves this vulnerability.

    Fixed in 0:7.0.27-1.el6
  3. Upgrade

    Upgrade redhat/rh-php70-php to a version that resolves this vulnerability.

    Fixed in 0:7.0.27-1.el7
  4. Upgrade

    Upgrade redhat/rh-php71-php to a version that resolves this vulnerability.

    Fixed in 0:7.1.30-1.el7
  5. Upgrade

    Upgrade redhat/php to a version that resolves this vulnerability.

    Fixed in 7.0.27
  6. Upgrade

    Upgrade redhat/php to a version that resolves this vulnerability.

    Fixed in 7.1.13
  7. Upgrade

    Upgrade redhat/php to a version that resolves this vulnerability.

    Fixed in 7.2.1
  8. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 7.0.30
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.6.33
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.0.27
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.1.13
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.2.1
  13. Compensating control

    For Apache sites configured to run .phar files using PHP, restrict or block HTTP requests for non-existent/invalid .phar paths at the web server (e.g., via routing rules or access controls) to prevent exposure of the PHAR 404 response that reflects the requested .phar URI parameter.

Event History

Jun 19, 2017
CVE Published
12:00 AM
Jan 16, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:08 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·04:05 PM
RemedyDescriptionSeverityAffected Software
Apr 28, 2026
Data Sourced
via Debian·04:54 PM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2018-5712?

CVE-2018-5712 is a vulnerability that allows for reflected XSS on the PHAR 404 error page in PHP.

2

What is the severity of CVE-2018-5712?

The severity of CVE-2018-5712 is medium with a CVSS score of 6.1.

3

Which versions of PHP are affected by CVE-2018-5712?

Versions before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1 are affected by CVE-2018-5712.

4

How can I fix CVE-2018-5712?

To fix CVE-2018-5712, update your PHP version to 5.6.33 or above, 7.0.27 or above, 7.1.13 or above, or 7.2.1 or above.

5

Where can I find more information about CVE-2018-5712?

You can find more information about CVE-2018-5712 in the following references: [1] [2] [3].

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203