PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. This can result in Possible information disclosure, possible impact on data integrity and execution of arbitrary code. References: https://bugs.mageia.org/show_bug.cgi?id=24185
Created php-pear-HTML-QuickForm tracking bugs for this issue: Affects: epel-all [bug 1668103]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.