CVE-2025-43717 Information

Description

In PEAR HTTP_Request2 before 2.7.0 multiple files in the tests directory notably tests/_network/getparameters.php and tests/_network/postparameters.php reflect any GET or POST parameters leading to XSS.

Reference

https://github.com/pear/HTTP_Request2/blob/b1c61b71128045734d757c4d3d436457ace80ea7/package.xml#L24 https://github.com/pear/HTTP_Request2/commit/07925aa77e441dba0ff0fa973a09802729cb838f https://github.com/pear/HTTP_Request2/commit/265e05f9e08a28a38a57219516a8e4e2dfdbb147 https://github.com/pear/HTTP_Request2/compare/v2.6.0…v2.7.0

Share on: