Lack of data validation In modsecurity-crs
Description
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 3.2.0-1 | ||
debian 14 | 3.2.0-1 | ||
debian 12 | 3.2.0-1 | ||
debian 13 | 3.2.0-1 |
Aliases
1. 2. 3. 4. 5.