CVE-2021-30134: XSS
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the postfilepathupload.php key parameter and the POST data to postmultidimensional.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30134?
CVE-2021-30134 has a moderate severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2021-30134?
To fix CVE-2021-30134, upgrade the affected PHP cURL extension wrapper to version 2.3.2 or later.
What is the impact of CVE-2021-30134?
The impact of CVE-2021-30134 is the possibility of XSS attacks, allowing malicious users to execute scripts in the context of a victim's browser.
Which software is affected by CVE-2021-30134?
CVE-2021-30134 affects multiple software including php-curl-class versions prior to 2.3.2 and various WordPress plugins.
How can I prevent exploitation of CVE-2021-30134?
To prevent exploitation of CVE-2021-30134, ensure that all affected software is updated to the latest secure version.