Skip to main content

PHP vulnerabilities

1 published alerts for PHP Group PHP.

Actively exploited (KEV)Ransomware

CVE-2024-4577

PHP-CGI OS Command Injection Vulnerability

PHP Group PHP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-4577). PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823. CISA remediation due date: 2024-07-03. If you need help checking exposure, call (864) 335-9223.