Type Casting Vulnerability in SimpleXMLElement_exportNode and simplexml_import_dom

Type Casting Vulnerability in SimpleXMLElement_exportNode and simplexml_import_dom

CVE-2016-1000004 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

Learn more about our Web Application Penetration Testing UK.