PHP Remote File Inclusion Affecting php-nesbot-carbon package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-PHPNESBOTCARBON-8610246
  • published10 Jan 2025
  • disclosed8 Jan 2025

Introduced: 8 Jan 2025

NewCVE-2025-22145  (opens in a new tab)
CWE-98  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 php-nesbot-carbon.

NVD Description

Note: Versions mentioned in the description apply only to the upstream php-nesbot-carbon package and not the php-nesbot-carbon package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6.