S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-37704 Scanner

CVE-2021-37704 scanner - Information Disclosure vulnerability in PhpFastCache

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-37704
4.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
phpfastcacheby PHPSocialNetwork
< 6.1.5
Updated Aug 21, 2026View on NVD →
Detail

PhpFastCache is a high-performance backend cache system widely used by developers for its efficiency and speed. It offers caching solutions for multiple platforms and databases, and can improve web page loading performance by storing frequently used data or objects in memory for quick retrieval. With its simple API and easy-to-use interface, PhpFastCache is a popular choice for website optimization and database performance enhancement.

Recently, a vulnerability known as CVE-2021-37704 has been discovered in certain versions of PhpFastCache. More specifically, versions prior to 6.1.5, 7.1.2, and 8.0.7 are vulnerable to this security issue. This vulnerability is particularly dangerous as it can expose sensitive information about the system, including the phpinfo() file to attackers. This file contains extensive information about the server configuration, PHP version and installed extensions, potentially enabling attackers to better target their attacks.

If exploited, CVE-2021-37704 can lead to serious security threats, such as leaking server-side information, leading to a possible remote code execution, which allows an attacker to execute arbitrary code on the server. This means that attackers could take full control over the web server, leading to potentially disastrous consequences for the website, its users, and the organization that operates it.

In conclusion, vulnerabilities such as CVE-2021-37704 are a serious threat to organizations and their digital assets. However, with the pro features of s4e.io platform, individuals and organizations can stay informed about security issues affecting their systems and take action to mitigate against potential risks. With the right security measures in place, developers can continue to enjoy the speed and efficiency of PhpFastCache without putting their systems or users in danger.

 

REFERENCES

Solution Advice

To protect against this vulnerability, developers using PhpFastCache are advised to take the following precautions:

  • Update to version 6.1.5, 7.1.2, or 8.0.7, which have been patched for this vulnerability.
  • If using an earlier version that is not supported, ensure that the vendor directory is protected from public access by placing it outside the web directory or using appropriate server rules (.htaccess, etc).
  • Regularly monitor and update PhpFastCache to stay protected against potential vulnerabilities.
  • Use trustworthy security measures to keep your servers and systems secure, as well as to regularly scan and test for vulnerabilities and risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-37704 scanner - Information Disclosure vulnerability in PhpFastCache | S4E