Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hhvm | * | 3.9.5 (excluding) | |
Hhvm | 3.10.0 (including) | 3.12.3 (including) | |
Hhvm | 3.13.0 (including) | 3.14.1 (including) | |
Hhvm | Ubuntu | esm-apps/xenial | * |
Hhvm | Ubuntu | upstream | * |
Hhvm | Ubuntu | xenial | * |