Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf3m-fq5f-p4q9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

EPSS

Процентиль: 54%
0.00308
Низкий

10 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 10
nvd
почти 8 лет назад

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

CVSS3: 10
debian
почти 8 лет назад

I Librarian I-librarian version 4.8 and earlier contains a XML Externa ...

EPSS

Процентиль: 54%
0.00308
Низкий

10 Critical

CVSS3

Дефекты

CWE-611