CVE-2021-21707 is a medium-severity vulnerability affecting PHP versions 7.3.x, 7.4.x, and 8.0.x, as well as products from Debian, NetApp, and Tenable. It stems from certain XML parsing functions URL-decoding filenames, potentially misinterpreting a URL-encoded NUL character as an end-of-filename marker. This could lead to unintended file access, allowing an attacker to read a different file than intended. The vulnerability has a CVSS score of 5.3, indicating a low impact on confidentiality with no integrity or availability impact, and does not require user interaction or privileges. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.3.0, < 7.3.33CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.26CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.13CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.