CVE-2025-34061
CVSS Score Not Available
76.30%
HIGH RiskEPSS (99th percentile)
A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes the payload without proper validation. This leads to remote code execution as the web server user, compromising the affected system.
Published: 7/3/2025
Modified: 7/8/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
76.30%HIGH Exploitation Risk
99th percentile
This vulnerability has a 76.30% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.