Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:14523
HistoryMay 02, 2019 - 4:52 a.m.

XML External Entity (XXE)

2019-05-0204:52:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

69.2%

php is vulnerable to XML external entity (XXE) attacks. It was found that the PHP SOAP parser allowed the expansion of external XML entities during SOAP message parsing. A remote attacker could possibly use this flaw to read arbitrary files that are accessible to a PHP application using a SOAP extension.

References