Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fjr-gm4j-5r6q

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.

An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.

EPSS

Процентиль: 60%
0.00402
Низкий

8.6 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.6
nvd
около 7 лет назад

An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.

EPSS

Процентиль: 60%
0.00402
Низкий

8.6 High

CVSS3

Дефекты

CWE-611