Vulnerability DatabaseGHSA-qffc-gwpp-m2xr

GHSA-qffc-gwpp-m2xr
PHP vulnerability analysis and mitigation

Overview

The XML External Entity (XXE) Processing vulnerability in TYPO3 Core (GHSA-qffc-gwpp-m2xr) was discovered and disclosed on February 23, 2016. This vulnerability affected TYPO3 CMS versions 6.2.0 to 6.2.18 and 7.6.0 to 7.6.3. The security issue was identified in the XML processing components of the TYPO3 Content Management System (TYPO3 Advisory, GitHub Advisory).

Technical details

The vulnerability allows for XML External Entity (XXE) processing within all XML processing components of the TYPO3 CMS. The severity was rated as High, with a suggested CVSS v2.0 score of AV:N/AC:M/Au:N/C:P/I:P/A:P/E:P/RL:O/RC:C. Systems using PHP with libxml2 version 2.9 or higher were protected by default, as this library version disallows external entity processing by default (TYPO3 Advisory).

Impact

The vulnerability could lead to the loading of internal and/or external file content within an XML structure. Additionally, it enabled potential attackers to inject arbitrary files for XML Denial of Service attacks, compromising system security and stability (TYPO3 Advisory, GitHub Advisory).

Exploitability

The vulnerability required network access and moderate complexity to exploit, with no authentication required as indicated by the CVSS metrics. The exploit proof was confirmed, as reflected in the CVSS scoring component RC:C (TYPO3 Advisory).

Mitigation and workarounds

The vulnerability was patched in TYPO3 versions 6.2.19 and 7.6.4. Users were advised to update to these versions to address the security issue. Additionally, systems using PHP with libxml2 version 2.9 or higher had built-in protection against this vulnerability due to the library's default security settings (TYPO3 Advisory, GitHub Advisory).

Community reactions

The security team member Marcus Krause was credited with discovering and reporting the issue. The TYPO3 team recommended users to follow the TYPO3 Security Guide and subscribe to the typo3-announce mailing list for future security updates (TYPO3 Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-52777CRITICAL9.4
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52775HIGH8.8
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52774MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52773MEDIUM6.1
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026
CVE-2026-52772MEDIUM5.5
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesSep 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management