CVE-2015-5723

Source
https://cve.org/CVERecord?id=CVE-2015-5723
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-5723.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-5723
Aliases
Downstream
Published
2016-06-07T14:06:08Z
Modified
2026-04-16T06:23:58.008730385Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

References

Affected packages