What is CVE-2026-17543?
This vulnerability allows for trivial SQL injection in PHP due to improper escaping of backslashes in attacker-provided parameters. It affects multiple PHP versions. Affected users are strongly advised to immediately update to the patched PHP versions.
Azərbaycanca: Bu zəiflik, PHP proqramında istifadəçi tərəfindən təqdim edilən parametrlərdəki backslash simvollarının düzgün təmizlənməməsi nəticəsində yaranan SQL injection hücumuna imkan verir. Bu problem PHP-nin bir neçə versiyasına təsir edir. İstifadəçilərə təcili olaraq müvafiq PHP versiyalarını yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What type of security issue does CVE-2026-17543 cause in PHP?
This vulnerability allows for trivial SQL injection due to improper escaping of backslashes in attacker-provided parameters.
What is recommended for users regarding CVE-2026-17543?
Affected users are strongly advised to immediately update to the patched PHP versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.