Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92h7-3mpg-68jh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.

Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.7
nvd
больше 4 лет назад

Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-611