{"id":"GHSA-r7c9-c69m-rph8","summary":"Code Injection in PHPUnit","details":"Util/PHP/eval-stdin.php in PHPUnit starting with 4.8.19 and before 4.8.28, as well as 5.x before 5.6.3, allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a `\u003c?php ` substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.","aliases":["CVE-2017-9841"],"modified":"2025-10-22T17:47:49.874745Z","published":"2022-03-26T00:19:30Z","database_specific":{"nvd_published_at":"2017-06-27T17:29:00Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-03-26T00:19:30Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9841"},{"type":"WEB","url":"https://github.com/sebastianbergmann/phpunit/pull/1955"},{"type":"WEB","url":"https://github.com/sebastianbergmann/phpunit/pull/1956"},{"type":"WEB","url":"https://github.com/sebastianbergmann/phpunit/commit/284a69fb88a2d0845d23f42974a583d8f59bf5a5"},{"type":"WEB","url":"https://github.com/sebastianbergmann/phpunit/commit/3aaddb1c5bd9b9b8d070b4cf120e71c36fd08412"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/phpunit/phpunit/CVE-2017-9841.yaml"},{"type":"PACKAGE","url":"https://github.com/sebastianbergmann/phpunit"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201711-15"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9841"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"WEB","url":"http://web.archive.org/web/20170701212357/http://phpunit.vulnbusters.com"},{"type":"WEB","url":"http://www.securityfocus.com/bid/101798"},{"type":"WEB","url":"http://www.securitytracker.com/id/1039812"}],"affected":[{"package":{"name":"phpunit/phpunit","ecosystem":"Packagist","purl":"pkg:composer/phpunit/phpunit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.8.19"},{"fixed":"4.8.28"}]}],"versions":["4.8.19","4.8.20","4.8.21","4.8.22","4.8.23","4.8.24","4.8.25","4.8.26","4.8.27"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-r7c9-c69m-rph8/GHSA-r7c9-c69m-rph8.json"}},{"package":{"name":"phpunit/phpunit","ecosystem":"Packagist","purl":"pkg:composer/phpunit/phpunit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.10"},{"fixed":"5.6.3"}]}],"versions":["5.0.10","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7","5.2.0","5.2.1","5.2.10","5.2.11","5.2.12","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.2.7","5.2.8","5.2.9","5.3.0","5.3.1","5.3.2","5.3.3","5.3.4","5.3.5","5.4.0","5.4.1","5.4.2","5.4.3","5.4.4","5.4.5","5.4.6","5.4.7","5.4.8","5.5.0","5.5.1","5.5.2","5.5.3","5.5.4","5.5.5","5.5.6","5.5.7","5.6.0","5.6.1","5.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-r7c9-c69m-rph8/GHSA-r7c9-c69m-rph8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H"}]}