php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

Project Subscriptions

Vendors Products
Ht Slider Range For Amazon Affiliates Project Subscribe
Ht Slider Range For Amazon Affiliates Subscribe
Php Curl Class Project Subscribe
Php Curl Class Subscribe
Ptwooplugins Subscribe
Invoicing With Invoicexpress For Woocommerce Subscribe
Woo-qiwi-payment-gateway Subscribe
Shopello Api Project Subscribe
Shopello Api Subscribe
Teamleade Subscribe
Teamleader Crm Forms Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f8p3-q834-q9cj php-mod/curl allows Cross-site Scripting
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-14T18:31:38.115Z

Reserved: 2021-04-05T00:00:00.000Z

Link: CVE-2021-30134

cve-icon Vulnrichment

Updated: 2024-08-03T22:24:59.641Z

cve-icon NVD

Status : Modified

Published: 2022-12-26T07:15:11.310

Modified: 2025-04-14T19:15:28.767

Link: CVE-2021-30134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses