Vulnerability record · CVE-2012-3363 · published 13 February 2013
CVE-2012-3363: Zend Framework Zend_XmlRpc XXE allows file read and SSRF
Zend · Zend Framework
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 mishandles SimpleXMLElement classes, so an external entity reference in a DOCTYPE element of an XML-RPC request is resolved. This is a classic XML external entity (XXE) injection that lets a remote attacker read arbitrary files or open outbound TCP connections from the server.
Description
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 3.1 base score is 9.1 (critical) with network reachability, no authentication, and high confidentiality and integrity impact.
What it is
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 mishandles SimpleXMLElement classes, so an external entity reference in a DOCTYPE element of an XML-RPC request is resolved. This is a classic XML external entity (XXE) injection that lets a remote attacker read arbitrary files or open outbound TCP connections from the server.
Impact
An attacker can read files accessible to the web/PHP process and use the server to make outbound TCP connections, exposing local data and enabling SSRF against internal services.
Attack surface
Reached over the network through the XML-RPC endpoint that parses attacker-supplied XML; the CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high (0.50248, 98.9th percentile) and public advisories and a patch reference exist, indicating meaningful real-world risk.
What to do
- Upgrade Zend Framework to 1.11.12 or 1.12.0 or later, or apply the vendor patch referenced in ZF2012-01.
- Update dependent applications and distributions (Moodle, Fedora, Debian) to versions containing the fix.
- Disable external entity and DOCTYPE processing in the XML parser used for XML-RPC requests.
- Restrict outbound network access from application servers to limit SSRF impact.
- Run the web/PHP process with least privilege and limit readable files.
Detection
- Search XML-RPC request logs for DOCTYPE declarations or SYSTEM/PUBLIC entity references.
- Monitor for unexpected outbound TCP connections from application servers.
- Alert on file access patterns consistent with XXE payloads (for example /etc/passwd or PHP filter wrappers).
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3363 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.