S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-30134 Scanner

CVE-2021-30134 scanner - Cross-Site Scripting (XSS) vulnerability in php-mod/curl Library

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-30134
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The php-mod/curl library is a popular PHP wrapper for the cURL extension that provides developers with easy-to-use functions and features for making HTTP requests, managing cookies and proxies, and performing file upload and download operations. This library is widely used in web application development and is favored for its efficient and flexible handling of HTTP requests and responses.

Recently, a new vulnerability has been detected in the php-mod/curl library, identified as CVE-2021-30134. This vulnerability allows for XSS (cross-site scripting) attacks via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. This means that an attacker could inject malicious code into a vulnerable website through user input fields, such as search bars or message forms, potentially leading to the theft of sensitive user data or the complete takeover of the website's functionality.

When exploited, this vulnerability can lead to serious consequences for both website owners and their users. For instance, an attacker could steal user credentials, spread malware, or even manipulate the website's content, causing harm or embarrassment to the website owner and its visitors. Moreover, XSS vulnerabilities are often difficult to detect and mitigate, especially when the website is complex and uses various third-party services.

In conclusion, the php-mod/curl library is a powerful and widely used tool for PHP developers, but the recent CVE-2021-30134 vulnerability has revealed the importance of proactive website security and risk management. By using specialized security platforms such as s4e.io, developers can easily and quickly learn about vulnerabilities in their digital assets, and take the necessary steps to prevent or mitigate potential threats. At s4e.io, we offer a range of pro features that can help enhance website security and ensure full protection against XSS attacks and other common web security risks.

 

REFERENCES

Solution Advice

To protect against CVE-2021-30134 and similar vulnerabilities, developers should take extra precautions when handling user input and data. Some recommended preventative measures include:

  • Sanitizing user input and performing validation checks to detect and block malicious code and characters.
  • Using robust server-side scripting languages and frameworks that include security mechanisms, such as input filtering and output escaping.
  • Applying strict Content Security Policies (CSP) that limit the execution of untrusted scripts and enforce HTTPS connections.
  • Keeping the php-mod/curl library and all other dependencies up to date by monitoring CVE databases and security bulletins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.