PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17082 - Vulnerability Database

PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17082

Medium
Reference: CVE-2018-17082
Title: PHP Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The Apache2 component in PHP before 5.6.38 7.0.x before 7.0.32 7.1.x before 7.1.22 and 7.2.x before 7.2.10 allows XSS via the body of a quotTransfer-Encoding: chunkedquot request because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.