Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67mv-4hj2-xp3g

Опубликовано: 11 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7

Описание

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.

EPSS

Процентиль: 1%
0.00106
Низкий

7 High

CVSS4

Дефекты

CWE-611

Связанные уязвимости

nvd
6 месяцев назад

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.

CVSS3: 7.3
fstec
6 месяцев назад

Уязвимость интерфейса рабочей станции EcoStruxure Building Operation Workstation и веб-интерфейса программного обеспечения EcoStruxure Building Operation WebStation, связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00106
Низкий

7 High

CVSS4

Дефекты

CWE-611