XML External Entity injection in getID3 - #VU150783
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to improper restriction of XML external entity references in the XML2array() function in getid3.lib.php when processing crafted XML metadata in uploaded media files. A remote attacker can upload a media file containing crafted XML metadata to disclose sensitive information and cause a denial of service.
The issue affects deployments running PHP versions earlier than 8.0.