CVE-2023-3823


Security issue with external entity loading in XML without enabling it

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. 



We have discovered 1,089,606 live websites that are affected by CVE-2023-3823.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 8 before 8.0.30
  • from 8.1 before 8.1.22
  • from 8.2 before 8.2.8
Total Vulnerable Versions507
Vulnerable Domains1,089,606 live websites (9.01% of PHP install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-3823 and the relative popularity of websites


Details

  • Published - Aug 11, 2023
  • Updated - Aug 11, 2023

Credits

  • Joas Schilling (reporter)




Countries

United States250,354 websites



Germany476,500 websites
France101,362 websites
Netherlands25,361 websites
GB22,393 websites
Russia21,018 websites
Canada14,535 websites
Italy13,237 websites
Japan11,337 websites
Spain11,272 websites

TLDs

.com560,007 websites
.de95,629 websites
.org59,971 websites
.fr45,090 websites
.net42,336 websites
.nl22,025 websites
.ru18,310 websites
.co.uk16,194 websites
.it11,218 websites
.info11,067 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-3823 through included software libraries and plugins.



References


Websites affected by CVE-2023-3823

Top websites that are affected by CVE-2023-3823. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.com United States***
***.******.com United States***
********.com United States***
************.com Germany***
******.org United States***
************.com United States***
*****.******.com United States***
**********.******.org United States***
***.******.net Germany*,***
****.com China*,***
See full domain list