Vulnerability DatabaseGHSA-229x-22xc-2f2w

GHSA-229x-22xc-2f2w
PHP vulnerability analysis and mitigation

Overview

A high-severity vulnerability was discovered in Zend_XmlRpc, identified as GHSA-229x-22xc-2f2w. The vulnerability affects Zendframework versions greater than or equal to 1.0.0 and less than 1.11.13. The issue was disclosed on June 22, 2012, and involves XML eXternal Entity (XXE) Injection attacks in the Zend_XmlRpc component (Zend Advisory, GitHub Advisory).

Technical details

The vulnerability stems from the insecure usage of the SimpleXMLElement class (SimpleXML PHP extension) when parsing XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. The vulnerability has been assigned a CVSS v3.1 score of 8.6 (High), with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The vulnerability is classified under CWE-611 (GitHub Advisory).

Impact

When exploited, this vulnerability allows attackers to coerce the application to open arbitrary files and/or TCP connections, potentially leading to unauthorized access to sensitive files on the system (Zend Advisory).

Exploitability

The vulnerability can be exploited remotely with low attack complexity and requires no privileges or user interaction. The attack vector is network-based, and the scope is changed, indicating that the vulnerable component impacts resources beyond its security scope (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched by implementing libxml_disable_entity_loader() in the Request and Response implementations of Zend_XmlRpc, which disables XXE parsing. Additional attack vectors were identified and patched in Zend_Dom, Zend_Feed, and Zend_Soap components. Users are recommended to upgrade to version 1.11.13 or greater immediately (Zend Advisory).

Community reactions

The vulnerability was identified and reported by Johannes Greil and Kestutis Gudinavicius from SEC Consult Vulnerability Lab, with additional vectors discovered by Pádraic Brady (Zend Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54182HIGH8.1
  • PHP logoPHP
  • backpack/crud
NoYesSep 14, 2026
CVE-2026-54178HIGH8.1
  • PHP logoPHP
  • backpack/crud
NoYesSep 14, 2026
CVE-2026-54180HIGH7.6
  • PHP logoPHP
  • backpack/crud
NoYesSep 14, 2026
CVE-2026-57570MEDIUM6.5
  • PHP logoPHP
  • backpack/crud
NoYesSep 14, 2026
CVE-2026-54181MEDIUM5.4
  • PHP logoPHP
  • backpack/crud
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management