Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-3363XML External Entity (XXE) Injection in Framework

Severity
9.1CRITICALNVD
NVD6.4
EPSS
55.1%
top 1.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 13
Latest updateMay 17

Description

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDzend/zend_framework1.0.01.11.12+56
Packagistzendframework/zendframework11.0.01.11.12+2

Also affects: Debian Linux 6.0, Fedora 17, 18

Patches

🔴Vulnerability Details

8
GHSA
Zend Framework XXE Vulnerability2022-05-17
OSV
Zend Framework XXE Vulnerability2022-05-17
GHSA
Zend Framework XEE Vulnerability2022-05-17
OSV
Zend Framework XEE Vulnerability2022-05-17
CVEList
CVE-2012-6531: (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 12013-02-13

💥Exploits & PoCs

1
Exploit-DB
Zend Framework < 2.0.0 beta4 < 1.12 RC1 < 1.11.11 - Local File Disclosure2012-06-27

📐Framework References

1
CWE
Improper Restriction of XML External Entity Reference

💬Community

7
Bugzilla
CVE-2012-3363 moodle: XXE via Zend library (MSA-13-0016)2013-03-25
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-17]2013-03-25
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-18]2013-03-25
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [epel-6]2013-03-25
Bugzilla
CVE-2012-3363 php-ZendFramework: File disclosure via XXE injection in Zend_XMLRPC (ZF2012-01)2012-06-26
CVE-2012-3363 — XML External Entity (XXE) Injection | cvebase