CVE-2012-4399

HIGH

CakePHP 2.1.0-2.1.4 and 2.1.0-alpha-2.1.4 - XML External Entity Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4399. PoCs published by Pawel Wylecial.

AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) injection vulnerability in CakePHP versions 2.x to 2.2.0-RC2. It allows an attacker to read arbitrary files from the server by crafting a malicious XML payload.

Description

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Pawel Wylecial · textwebappsphp
https://www.exploit-db.com/exploits/19863

This exploit demonstrates an XXE (XML External Entity) injection vulnerability in CakePHP versions 2.x to 2.2.0-RC2. It allows an attacker to read arbitrary files from the server by crafting a malicious XML payload.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: CakePHP 2.x - 2.2.0-RC2
No auth needed
Prerequisites: Ability to send crafted XML requests to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49900
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2012/Jul/101
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19863
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/84042
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/03/1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/03/2

Scores

CVSS v3 7.5
EPSS 0.2266
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (2)
cakefoundation/cakephp 2.1.0 - 2.1.5
cakephp/cakephp 2.1.0-alpha - 2.1.5Packagist
Published Oct 09, 2012
Tracked Since Feb 18, 2026