← Back

CVE-2021-21707

nvd nist
Published: Nov 29, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

Affected (7)

Products: Php: Php · Netapp: Clustered Data Ontap · Debian: Debian Linux · +1 more
Show all products
1 product
Php
1 product
Clustered Data Ontap
1 product
Debian Linux
1 product
Tenable.sc
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.3.0 to 7.3.33
From 7.4.0 to 7.4.26
From 8.0.0 to 8.0.13
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.21.0

References (10)

Source: security@php.net
ExploitIssue TrackingPatchRelease NotesVendor Advisory
Source: security@php.net
Issue TrackingMailing List
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
PatchRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesThird Party Advisory

Timeline

No history available yet.