AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-5723

HIGH · CVSS 7.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-06-07 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects MongoDB.

CVE
CVE-2015-5723
Severity
HIGH
CVSS
7.8
EPSS
0.38%
MongoDB

Original NVD Description

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.