Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hxq-vv35-9r5r

Опубликовано: 08 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

EPSS

Процентиль: 100%
0.92287
Критический

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

EPSS

Процентиль: 100%
0.92287
Критический

7.5 High

CVSS3

Дефекты

CWE-611