VDB
Sign up
CRITICAL9.8

GHSA-r7c9-c69m-rph8

Code Injection in PHPUnit

Quick fix

GHSA-r7c9-c69m-rph8 — phpunit/phpunit: upgrade to the fixed version with the command below.

composer require phpunit/phpunit:^4.8.28

Details

Util/PHP/eval-stdin.php in PHPUnit starting with 4.8.19 and before 4.8.28, as well as 5.x before 5.6.3, allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a `<?php ` substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpunit/phpunit
Introduced in: 4.8.19Fixed in: 4.8.28
Fixcomposer require phpunit/phpunit:^4.8.28
Packagist/phpunit/phpunit
Introduced in: 5.0.10Fixed in: 5.6.3
Fixcomposer require phpunit/phpunit:^5.6.3

References