CVE-2022-31109 affects laminas-diactoros, a PHP package, allowing attackers to manipulate the host, protocol, or port of a URI instance via X-Forwarded-* headers if the application is not behind a trusted proxy. This medium-severity vulnerability (CVSS 6.1) can lead to Cross-Site Scripting (XSS) and URL poisoning, requiring user interaction (UI:R) for exploitation. While the vulnerability has a low EPSS score and no known active exploitation, exploit code, or significant community discussion, users are advised to upgrade to version 2.11.1 or later, or configure web servers to reject X-Forwarded-* headers as a mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.1CPE matchmatch criteria | cpe:2.3:a:getlaminas:laminas-diactoros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.