CVE-2013-1824: Apple Mac OS X
Medium severity, CVSS 4.3. EPSS: 4.3% chance of exploitation in the next 30 days.
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
Affected products
- Apple Mac OS X: from 10.0.0, before 10.8.5 (fixed in 10.8.5)
- PHP PHP: before 5.3.22 (fixed in 5.3.22); from 5.4.0, before 5.4.12 (fixed in 5.4.12)
- Red Hat Enterprise Linux: version 5 only; version 6.0 only
Published 2013-09-16. Last modified 2026-06-16.