Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c2v-98pf-9vgr

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

EPSS

Процентиль: 18%
0.00059
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

EPSS

Процентиль: 18%
0.00059
Низкий

7.5 High

CVSS3

Дефекты

CWE-611