PHPUnit Command Injection Vulnerability

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

Published 27 Jun 2017Updated 16 Jun 202614 sources
CVSS 9.8 ✓ VERIFIED REFERENCE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.