CVE-2012-4399

EUVD-2022-2545
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
cakefoundationcakephp
2.1.0 ≤
𝑥
< 2.1.5
cakefoundationcakephp
2.2.0 ≤
𝑥
< 2.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cakephp
bullseye
2.10.11-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cakephp
hardy
not-affected
lucid
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected