Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g33j-xwrp-hpfv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

EPSS

Процентиль: 63%
0.00441
Низкий

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.2
nvd
почти 5 лет назад

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

EPSS

Процентиль: 63%
0.00441
Низкий

Дефекты

CWE-611