Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sad-Spirit

#40221of 53,624
6.8Total CVSS
Vulnerabilities · 1
PT-2025-16930
6.8
2025-03-14
Pear · Pear Http Request2 · CVE-2025-43717
**Name of the Vulnerable Software and Affected Versions** PEAR HTTP Request2 versions prior to 2.7.0 **Description** The issue concerns multiple files in the tests directory of PEAR HTTP Request2, specifically tests/ network/getparameters.php and tests/ network/postparameters.php, which reflect any GET or POST parameters. This reflection leads to a cross-site scripting (XSS) issue. **Recommendations** For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the tests directory, specifically to the files tests/ network/getparameters.php and tests/ network/postparameters.php, until the update is applied.