CVE-2025-43717

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.
Configurations

No configuration.

History

17 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 03:15

Updated : 2025-04-17 20:21


NVD link : CVE-2025-43717

Mitre link : CVE-2025-43717

CVE.ORG link : CVE-2025-43717


JSON object : View

Products Affected

No product.

CWE
CWE-531

Inclusion of Sensitive Information in Test Code