VDB
Sign up
HIGH8.6

GHSA-229x-22xc-2f2w

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

Quick fix

GHSA-229x-22xc-2f2w — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.11.13

Details

Zend_XmlRpc is vulnerable to XML eXternal Entity (XXE) Injection attacks. The SimpleXMLElement class (SimpleXML PHP extension) is used in an insecure way to parse XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. By exploiting this vulnerability an application may be coerced to open arbitrary files and/or TCP connections.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.0.0Fixed in: 1.11.13
Fixcomposer require zendframework/zendframework1:^1.11.13

References