VDB
Sign up
HIGH7.3

GHSA-7pg4-5233-82jv

Zend Framework XXE Vulnerability

Quick fix

GHSA-7pg4-5233-82jv — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.11.12

Details

`Zend_XmlRpc` in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle `SimpleXMLElement` classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.0.0Fixed in: 1.11.12
Fixcomposer require zendframework/zendframework1:^1.11.12
Packagist/zendframework/zendframework1
Introduced in: 1.12.0-rc1Fixed in: 1.12.0
Fixcomposer require zendframework/zendframework1:^1.12.0

References