-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability GHSA-3fgr-xjr6-xqm8 explicitly cites Wrapper::buildClientWrapperCode as the entry point. The commit diff shows the fix added escaping for backslashes (\\) and quotes (\') in the client's path/server properties, addressing code injection via crafted $client arguments. The CWE-95 (Eval Injection) classification confirms this is a case of improper neutralization in dynamically evaluated code generation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| phpxmlrpc/phpxmlrpc | composer | < 4.9.0 | 4.9.0 |
KEV Misses 88% of Exploited CVEs- Get the report