peter bassill · operator
$ cve CVE-2015-5161 JSON

CVE-2015-5161 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS9.87% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2015-08-25
Last modified2026-06-17

Affected (1)

VendorProduct
zendzend framework

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD