Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hr6-vc97-qxxh

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

XML Injection in Crafter CMS Crafter Studio 3.0.1

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

Пакеты

Наименование

org.craftercms:crafter-studio

maven
Затронутые версииВерсия исправления

<= 3.0.1

3.0.2

EPSS

Процентиль: 84%
0.02272
Низкий

8.6 High

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 8.6
nvd
около 5 лет назад

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

EPSS

Процентиль: 84%
0.02272
Низкий

8.6 High

CVSS3

Дефекты

CWE-91