Unrated severityNVD Advisory· Published Nov 29, 2021· Updated Sep 17, 2024
Special characters break path parsing in XML functions
CVE-2021-21707
Description
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.debian.org/security/2022/dsa-5082mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlmitremailing-list
- bugs.php.net/bug.phpmitre
- security.netapp.com/advisory/ntap-20211223-0005/mitre
- www.tenable.com/security/tns-2022-09mitre
News mentions
0No linked articles in our index yet.