CVE-2023-49283 is a medium-severity vulnerability affecting the Microsoft Graph Library for PHP (microsoft-graph-core) versions prior to 2.0.2. It allows for information disclosure due to test code that enables the phpInfo() function, exposing system details like configuration and environment variables. Exploitation requires a misconfigured server where the /vendor directory is web-accessible, enabling an unauthenticated attacker to craft an HTTP request to execute the function. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.2CPE matchmatch criteria | cpe:2.3:a:microsoft:graph:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.