Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11501 | In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS. |
Github GHSA |
GHSA-w7gh-f2fm-9q8r | PEAR HTTP_Request2 vulnerable to Cross-site Scripting |
Thu, 17 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Apr 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS. | |
| Weaknesses | CWE-531 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-17T19:16:25.268Z
Reserved: 2025-04-17T00:00:00.000Z
Link: CVE-2025-43717
Updated: 2025-04-17T19:16:20.020Z
Status : Deferred
Published: 2025-04-17T03:15:16.640
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-43717
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA