peter bassill · operator
$ cve CVE-2012-4399 JSON

CVE-2012-4399 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 12.1% (pctl 96)

Patch early

A public exploit exists.

Description

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS12.09% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2012-10-09
Last modified2026-06-16

Affected (1)

VendorProduct
cakefoundationcakephp

Public exploits

SourceTitleDate
exploit-dbCakePHP 2.x < 2.2.0-RC2 - XML External Entity Injection2012-07-16

References

→ the Explorer  ·  watch your stack  ·  NVD