REDHAT-BUG-2468562: XSS
In PHP versions 8.2. before 8.2.31, 8.3. before 8.3.31, 8.4. before 8.4.21, 8.5. before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.2.31 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.3.31 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.4.21 - Upgrade
Upgrade
phpto a version that resolves this vulnerability.Fixed in 8.5.6
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2468562?
The severity of REDHAT-BUG-2468562 is medium, rated at 4.
How do I fix REDHAT-BUG-2468562?
To fix REDHAT-BUG-2468562, upgrade to PHP versions 8.2.31, 8.3.31, 8.4.21, or 8.5.6 or later.
What type of vulnerability is REDHAT-BUG-2468562?
REDHAT-BUG-2468562 is a cross-site scripting (XSS) vulnerability due to improper sanitation of user data.
Which versions of PHP are affected by REDHAT-BUG-2468562?
PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6 are affected by REDHAT-BUG-2468562.
What can an attacker do with REDHAT-BUG-2468562?
An attacker can exploit REDHAT-BUG-2468562 to execute arbitrary JavaScript code on the target's machine.