← Back to browse · API

CVE-2022-31629

Severity
MEDIUM
CVSS
6.5
EPSS
0.49336
Risk score
43.27
CISA KEV
No
PoC
No
Published
2022-09-28
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2022-53081, GHSA-C43M-486J-J32P
Products
PHP Group:PHP 7.4.X <7.4.31, PHP Group:PHP 8.0.X <8.0.24, PHP Group:PHP 8.1.X <8.1.11
Sources
euvd EUVD-2022-53081

Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

References