← Vulnerability feed

Vulnerability record · CVE-2012-1102 · published 9 July 2021

CVE-2012-1102: Xml\ \ xml external entity (xxe) vulnerability

XXml\ · \

It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.

7.5 CVSS 3.1 High EPSS 1.4% · top 28.6% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://metacpan.org/release/MIYAGAWA/XML-Atom-0.39/source/Changes Release NotesThird Party Advisory
https://seclists.org/oss-sec/2012/q1/549 ExploitMailing ListThird Party Advisory
https://metacpan.org/release/MIYAGAWA/XML-Atom-0.39/source/Changes Release NotesThird Party Advisory
https://seclists.org/oss-sec/2012/q1/549 ExploitMailing ListThird Party Advisory

Track CVE-2012-1102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-40934Xml\ \ improper verification of cryptographic signature vulnerabilityXML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the …EPSS 0.16%9.1CVE-2026-9487Xml\ \ improper verification of cryptographic signature vulnerabilityXML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves…EPSS 0.28%9.1CVE-2026-9390Xml\ \ vulnerabilityXML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions b…EPSS 0.51%7.5CVE-2026-18568Xml\ \ improper verification of cryptographic signature vulnerabilityXML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped bef…EPSS 0.32%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed7.5CVE-2023-45727Proself XXE flaw allows unauthenticated file readProself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote…KEVEPSS 3.5%analysed

Source: NIST National Vulnerability Database (record CVE-2012-1102), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.