Junglewise Threat Intelligence

XML-RPC for PHP's `Wrapper::buildClientWrapperCode` method allows code injection via malicious `$client` argument

Severity: info · Published 2023-01-11

Technologies: phpxmlrpc/phpxmlrpc (Packagist). Vendors: Packagist.

Executive brief

XML-RPC for PHP's `Wrapper::buildClientWrapperCode` method allows code injection via malicious `$client` argument

Affected products

  • Packagist phpxmlrpc/phpxmlrpc

Related threats