PHP Code Execution Vulnerability in Doctrine Annotations and Cache by Doctrine Project
CVE-2015-5723
7.8HIGH
Key Information:
- Vendor
Zend
- Status
- Vendor
- CVE Published:
- 7 June 2016
What is CVE-2015-5723?
The vulnerability in Doctrine Annotations and other components allows local users to exploit improperly configured permissions on cache directories. This misconfiguration permits the execution of arbitrary PHP code by leveraging applications with a umask set to 0, posing significant security risks. Attackers can manipulate cache entries, gaining elevated privileges and compromising system integrity.