PT-2024-40512 · Unknown · Phpxmlrpc/Extras

Published

2024-05-20

·

Updated

2024-05-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpxmlrpc/extras versions prior to 0.6.1
Description The issue exists within the class documenting xmlrpc server when processing the methodName parameter in GET requests, specifically through the API endpoint, allowing for a Cross-Site Scripting (XSS) attack.
Recommendations For versions prior to 0.6.1, update to version 0.6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the documenting xmlrpc server class or avoiding the use of the methodName parameter in GET requests until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

GHSA-WW6P-Q26W-FR6M

Affected Products

Phpxmlrpc/Extras