Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67m6-wgh8-4vh7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

EPSS

Процентиль: 64%
0.00463
Низкий

8.6 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.6
nvd
около 7 лет назад

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

EPSS

Процентиль: 64%
0.00463
Низкий

8.6 High

CVSS3

Дефекты

CWE-611