CVE-2025-43717

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) En PEAR HTTP_Request2 anterior a 2.7.0, varios archivos en el directorio de pruebas, especialmente tests/_network/getparameters.php y tests/_network/postparameters.php, reflejan cualquier parĂ¡metro GET o POST, lo que genera XSS.

17 Apr 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 03:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-43717

Mitre link : CVE-2025-43717

CVE.ORG link : CVE-2025-43717


JSON object : View

Products Affected

No product.

CWE
CWE-531

Inclusion of Sensitive Information in Test Code