FlawAtlas
Search the atlas
CVE-2015-5161 Moderate

ZendXml and Zend Framework contain XXE and XEE Vulnerabilities

The `Zend_Xml_Security::scan` in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Exploit probability 9.9%
Published May 17, 2022
Required by Not available
Last source change December 4, 2024

02 / AFFECTED SOFTWARE

Affected packages

Packagist zendframework/zendframework

55 explicit affected versions

Packagist zendframework/zendframework1

14 explicit affected versions

Packagist zendframework/zendxml

1 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-xp8p-9rq5-4wgv

The `Zend_Xml_Security::scan` in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

View original source

05 / REFERENCES

Further evidence