Vulnerability DatabaseGHSA-5vv7-j593-mgjc

GHSA-5vv7-j593-mgjc
PHP vulnerability analysis and mitigation

Overview

Neos Flow, a PHP framework, was found to contain two significant security vulnerabilities. The first issue allowed arbitrary file uploads, including server-side scripts, in version 3.0.0. The second vulnerability involved XML External Entity (XXE) processing in the MediaTypeConverter component affecting versions 2.3.0 to 2.3.6. These vulnerabilities were discovered and disclosed on November 23rd, 2015, with a medium severity rating (Neos Blog).

Technical details

The vulnerability primarily manifests in two ways: First, Flow 3.0.0 removed previous restrictions on PHP file uploads, allowing potential malicious script uploads. Prior versions had specifically blocked .php file extensions. Second, versions 2.3.0 to 2.3.6 contained a potential XML External Entity processing vulnerability in the MediaTypeConverter component. The issue was assigned a suggested CVSS v2.0 score of (AV:N/AC:L/Au:S/C:P/I:P/A:N/E:ND/RL:OF/RC:C) (Neos Blog).

Impact

If exploited, the arbitrary file upload vulnerability could lead to several severe consequences including information disclosure, placement of backdoors, and data removal, particularly if uploaded scripts are executed through their public URL. However, the actual risk depends on the system setup and whether the application built on Flow provides file upload capabilities. The impact is only relevant if uploaded script files can be executed by the server (GitHub Advisory).

Exploitability

The exploitability of the file upload vulnerability is contingent on whether the application built on Flow provides means for file uploads and the system's configuration. The vulnerability is only exploitable if uploaded script files can be executed by the server when accessed through their public URL (Neos Blog).

Mitigation and workarounds

The issues were addressed in Flow versions 2.3.8 and 3.0.2. Flow 3.0.2 introduced a blacklist for file extensions that may be uploaded and/or published, which includes extensions used by popular scripting languages. The execution of server-side scripts in the public resources folder was disabled by default on Apache. Additionally, the processing of external entities when loading XML in the MediaTypeConverter was disabled in both Flow releases. Note that versions 2.3.7 and 3.0.1 contained minor regressions that were subsequently fixed (Neos Blog).

Community reactions

The vulnerability was discovered through responsible disclosure by Mickael Dorigny from Synetis (file upload issue) and Wouter Wolters (XXE problem). The fixes were sponsored by Flownative and networkteam, and reviewed by the Neos security team (Neos Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-wg23-69c2-gjc8CRITICAL9.1
  • PHP logoPHP
  • craftcms/cms
NoYesAug 07, 2026
CVE-2026-71488HIGH7.5
  • PHP logoPHP
  • php-league-commonmark
NoYesAug 06, 2026
CVE-2026-62996MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026
CVE-2026-62992MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026
CVE-2026-71478MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management