Cyber Posture

CVE-2024-57063

High

Published: 05 February 2025

Published
05 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0036 57.8th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

Security Summary

CVE-2024-57063 is a prototype pollution vulnerability in the lib function of the php-date-formatter library version 1.3.6. This issue enables attackers to cause a Denial of Service (DoS) condition by supplying a crafted payload. The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is classified under CWE-1321.

Remote attackers can exploit this vulnerability over the network without authentication, privileges, or user interaction, using low-complexity techniques. Successful exploitation results in high-impact disruption to availability, leading to a DoS, with no effects on confidentiality or integrity.

Mitigation details are available in the referenced advisory at https://gist.github.com/tariqhawis/dcb93b4788273c3ffb15f70dc45ca4e7.

Details

CWE(s)
CWE-1321

References