{"id":"GHSA-3fgr-xjr6-xqm8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3fgr-xjr6-xqm8","summary":"code injection in phpxmlrpc/phpxmlrpc","details":"code injection in `Wrapper::buildClientWrapperCode` via manipulation of the `$client` argument. It was possible to force the client to access local files or connect to undesired urls instead of the intended target server's url.","published":"2022-11-28T22:07:33Z","modified":"2024-12-07T05:40:22.116741Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"phpxmlrpc/phpxmlrpc","fixedVersion":"4.9.0"}],"fix":{"url":"https://github.com/gggeek/phpxmlrpc/commit/cf6e605e09d001ce520bfa8e7b168cfa514e663b","label":"gggeek/phpxmlrpc@cf6e605"},"references":[{"type":"WEB","url":"https://github.com/gggeek/phpxmlrpc/issues/80"},{"type":"WEB","url":"https://github.com/gggeek/phpxmlrpc/commit/cf6e605e09d001ce520bfa8e7b168cfa514e663b"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/phpxmlrpc/phpxmlrpc/2022-11-28-2.yaml"},{"type":"PACKAGE","url":"https://github.com/gggeek/phpxmlrpc"},{"type":"WEB","url":"https://github.com/gggeek/phpxmlrpc/releases/tag/4.9.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-07T05:40:22.116741Z"}}