Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7m6-xxhh-82qr

Опубликовано: 19 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 33%
0.00131
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость функции RequestInfoByXml реализации программного интерфейса API платформы для совместной работы и автоматизации делопроизводства Weaver e-cology, позволяющая нарушителю получить доступ на чтение, изменение, или удаление данных

EPSS

Процентиль: 33%
0.00131
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611