We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-43717



Description

In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.

Reserved 2025-04-17 | Published 2025-04-17 | Updated 2025-04-17 | Assigner mitre


MEDIUM: 5.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-531 Inclusion of Sensitive Information in Test Code

Product status

Default status
unaffected

Any version before 2.7.0
affected

References

github.com/...ommit/07925aa77e441dba0ff0fa973a09802729cb838f

github.com/...ommit/265e05f9e08a28a38a57219516a8e4e2dfdbb147

github.com/pear/HTTP_Request2/compare/v2.6.0...v2.7.0

github.com/...71128045734d757c4d3d436457ace80ea7/package.xml

cve.org (CVE-2025-43717)

nvd.nist.gov (CVE-2025-43717)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-43717

Support options

Helpdesk Chat, Email, Knowledgebase