Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8927


In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.


Published

2024-10-08T04:15:10.867

Last Modified

2025-11-03T23:17:33.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-1220

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php < 8.1.30 Yes
Application php php < 8.2.24 Yes
Application php php < 8.3.12 Yes

References