CVE-2012-4399: XEE
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4399?
CVE-2012-4399 is considered a medium severity vulnerability due to its potential to allow unauthorized file access through XML external entity injection.
How do I fix CVE-2012-4399?
To fix CVE-2012-4399, upgrade to CakePHP version 2.1.5 or 2.2.1 or later, which include the necessary security patches.
Which versions of CakePHP are affected by CVE-2012-4399?
CVE-2012-4399 affects CakePHP versions 2.1.x before 2.1.5 and 2.2.x before 2.2.1.
What type of attack does CVE-2012-4399 enable?
CVE-2012-4399 enables XML external entity (XXE) injection attacks, allowing remote attackers to read arbitrary files.
Is CVE-2012-4399 a common vulnerability?
CVE-2012-4399 is known within the CakePHP community and is recognized as a common vulnerability affecting certain versions.