CVE-2012-4399: Cakefoundation Cakephp
High severity, CVSS 7.5. EPSS: 12.1% chance of exploitation in the next 30 days.
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Affected products
- Cakefoundation Cakephp: from 2.1.0, before 2.1.5 (fixed in 2.1.5); from 2.2.0, before 2.2.1 (fixed in 2.2.1)
Published 2012-10-09. Last modified 2026-06-16.