Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hrg-9j2r-pwqr

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

EPSS

Процентиль: 55%
0.00321
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.6
ubuntu
больше 7 лет назад

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

CVSS3: 9.6
nvd
больше 7 лет назад

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

EPSS

Процентиль: 55%
0.00321
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-611