Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-11045
HistoryDec 23, 2019 - 3:15 a.m.

Design/Logic Flaw

2019-12-2303:15:00
PRIOn knowledge base
www.prio-n.com
13

7.2 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.8%

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.