CyberRota
Live Feed
Return to register
Case File

CVE-2012-6531

MEDIUM · CVSS 6.4 EPSS 2.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-02-13 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-6531
Severity
MEDIUM
CVSS
6.4
EPSS
2.52%

Original Filing — NVD Description

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.