CVE-2020-7061
PoC —CVSS 3.1
9.1 critical
EPSS
4%p90
Published
()
Modified
Description
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
In the news0 stories
No ingested article mentions this CVE yet.