Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pj2p-4hq9-w6vq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

EPSS

Процентиль: 80%
0.0141
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.9
nvd
больше 8 лет назад

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

EPSS

Процентиль: 80%
0.0141
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-611