Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw37-c6q4-x7h9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

EPSS

Процентиль: 70%
0.00622
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

EPSS

Процентиль: 70%
0.00622
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-611