CVE-2021-21702


Null Dereference in SoapClient

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.



We have discovered 830,634 live websites that are affected by CVE-2021-21702.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.27
  • from 7.4 before 7.4.15
  • from 8 before 8.0.2
Total Vulnerable Versions507
Vulnerable Domains830,634 live websites (6.87% of PHP install base)


Common Weakness Enumeration


CWE-476 NULL Pointer Dereference


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-21702 and the relative popularity of websites


Details

  • Published - Feb 1, 2021
  • Updated - Oct 20, 2021

Credits

  • Reported by jgalindo at datto dot com





Countries

United States318,595 websites



France245,470 websites
Germany19,868 websites
Canada19,136 websites
GB18,692 websites
Russia18,623 websites
Poland16,405 websites
Spain14,311 websites
Italy14,285 websites
China13,428 websites

TLDs

.com428,585 websites
.fr109,155 websites
.org50,026 websites
.net26,427 websites
.ru15,624 websites
.be13,085 websites
.pl12,745 websites
.de11,669 websites
.co.uk11,601 websites
.ca11,188 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-21702 through included software libraries and plugins.



References


Websites affected by CVE-2021-21702

Top websites that are affected by CVE-2021-21702. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
*******.com Germany*,***
***************.org United States*,***
***.**.gov United States*,***
******.com France*,***
**********.com France*,***
********.org United States*,***
***.*********.com United States*,***
****.**********.***.uk GB*,***
****.******.jp Japan*,***
See full domain list