VULNERABILITY INTELLIGENCE

CVE-2011-4107

CVSS score6.5 MEDIUM
EPSS probability12.68%
CISA KEVNot currently listed
Published2011-11-17
Last modified2026-06-16
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Weakness classification

  • CWE-611: Improper Restriction of XML External Entity Reference

Primary references