Php-mod/curl library before 2.3.2 contains a cross-site scripting vulnerability via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. An attacker can inject arbitrary script, which can allow theft of cookie-based authentication credentials and launch of other attacks.
id: CVE-2021-30134
info:
name: Php-mod/curl Library <2.3.2 - Cross-Site Scripting
author: theam
...