VYPR
High severity7.5NVD Advisory· Published Oct 9, 2012· Updated Apr 29, 2026

CVE-2012-4399

CVE-2012-4399

Description

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cakephp/cakephpPackagist
>= 2.1.0-alpha, < 2.1.52.1.5
cakephp/cakephpPackagist
>= 2.2.0-beta, < 2.2.12.2.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.