PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue has been patched in version 1.33.0.
The vulnerability results from the use of the preg_replace() function with the /e modifier in code handling email notifications about bug reports. The /e modifier causes the replacement string to be evaluated as PHP code. If an attacker is able to supply controlled content to the replacement expression (e.g., through a crafted bug report), it will be executed as PHP code on the server.
An attacker can gain the ability to execute arbitrary PHP code remotely on the server (RCE), which consequently may lead to complete system compromise, data theft, or further lateral movement in the infrastructure.
PEAR Pearweb should be updated to version 1.33.0 or newer, where the issue has been fixed. Detailed information is available in the vendor references: https://github.com/pear/pearweb/security/advisories/GHSA-vhw6-hqh9-8r23
PEAR Pearweb in versions earlier than 1.33.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XPear Pearweb
APPPear< 1.33.0
Related vulnerabilities
SQL injection w PEAR Pearweb — nieuwierzytelniony dostęp przez endpoint /get/
SQL Injection w PEAR Pearweb — podatność przy usuwaniu subskrypcji błędów
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable ...
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in...
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL inject...