Description
PHPUnit is a programmer-oriented testing framework for PHP. PHPUnit 4.x versions before 4.8.28 and 5.x versions before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a <?php substring. This vulnerability is exploitable only if the /vendor folder is publicly accessible.
Remediation
Upgrade to the latest version of PHPUnit. This issue was fixed in PHPUnit versions 4.8.28 and 5.6.3.
References
Related Vulnerabilities
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)
Apache Unomi MVEL RCE (CVE-2020-13942)
Drupal Core 8.6.x Remote Code Execution (8.6.0 - 8.6.9)
Cacti Unauthenticated Command Injection (CVE-2022-46169)
WordPress Plugin Arigato Autoresponder and Newsletter Remote Code Execution (2.5.1.9)