CC-4508 – Critical Vulnerability in PHP

Status Published


In versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using and PHP-CGI on , if the system is set up to use certain pages, Windows may use “Best-Fit” behavior to replace characters in line given to . PHP CGI module may misinterpret those characters as PHP options,

Read more