CVE DATABASE / CVE-2012-4399
CVE-2012-4399
CVSS 7.5 · HIGH
Summary
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
CVSS 3.1 breakdown
| Base score | 7.5 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | NONE |
| Availability | NONE |
Weakness type (CWE)
Affected products
Cakefoundation cakephp
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://bakery.cakephp.org/articles/markstory/2012/07/14/security_release_-_cakephp_2_1_5_2_2_1
- http://seclists.org/bugtraq/2012/Jul/101
- http://secunia.com/advisories/49900
- http://www.exploit-db.com/exploits/19863
- http://www.openwall.com/lists/oss-security/2012/09/03/1
- http://www.openwall.com/lists/oss-security/2012/09/03/2
- http://www.osvdb.org/84042
Data: NIST NVD. NVD last modified 2026-04-29. Always verify against the vendor advisory before acting.