Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44q2-5cm4-72hw

Опубликовано: 29 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

EPSS

Процентиль: 17%
0.00054
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

EPSS

Процентиль: 17%
0.00054
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-611