PT-2026-94253 · Git+1 · Sachertortephp
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
sachertortephp (affected versions not specified)
Description
A logic error exists in the
Xml::build() static method within the lib/Cake/Utility/Xml.php file. The issue stems from incorrect operator precedence in a conditional statement intended to control network-based XML fetching. Specifically, the expression evaluates the https:// check independently of the readFile option. Consequently, if an attacker controls the input parameter, they can force the application to perform an outbound HTTPS request via HttpSocket even when the readFile option is set to false. This leads to Server-Side Request Forgery (SSRF), potentially allowing information disclosure from internal services or external targets by parsing the fetched response as XML.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict user-controlled input from reaching the
input parameter of the Xml::build() function.Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sachertortephp