Skip to main content

CVE-2025-34061

CVSS Score Not Available
76.30%
HIGH RiskEPSS (99th percentile)

A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes the payload without proper validation. This leads to remote code execution as the web server user, compromising the affected system.

Published: 7/3/2025
Modified: 7/8/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

76.30%HIGH Exploitation Risk
99th percentile

This vulnerability has a 76.30% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.