Phpservermonitor is a narrowly scoped web-based server-monitoring application vulnerable to a modest set of input-handling and cryptographic weaknesses, centered on CSRF, CRLF injection, and insufficient entropy in random value generation. These weakness classes reflect the challenge of securing session management and request validation in a web application with direct server access. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpservermonitor over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18921MEDIUM PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action. | Dec 18, 2018 | 6.5 | 22 | NO | NO |
CVE-2021-4097MEDIUM phpservermon is vulnerable to Improper Neutralization of CRLF Sequences | Dec 12, 2021 | 5.4 | 21 | NO | NO |
CVE-2021-4241MEDIUM A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation lea | Nov 15, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-4240MEDIUM A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The mani | Nov 15, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpservermonitor.
Media articles that mention a CVE ID that affects a product developed by Phpservermonitor — matched by CVE ID, not by vendor name.