CVE-2024-1874
CRITICALDescription
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
Is your site exposed to CVE-2024-1874?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| php | php |
| php | php |
| php | php |
| fedoraproject | fedora |
| fedoraproject | fedora |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2024-1874? +
How severe is CVE-2024-1874? +
What products are affected by CVE-2024-1874? +
How do I check if I'm vulnerable to CVE-2024-1874? +
Related Vulnerabilities
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to …
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This …
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue …
A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of …
Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive …