Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23597
HistoryApr 10, 2020 - 12:31 a.m.

Authorization Bypass

2020-04-1000:31:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0

Percentile

0.4%

php is vulnerable to authorization bypass. A flaw was found in the handling of the β€œmbstring.func_overload” configuration setting. A value set for one virtual host, or in a user’s .htaccess file, was incorrectly applied to other virtual hosts on the same server, causing the handling of multibyte character strings to not work correctly.

References