Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqc2-6qq8-p574

Опубликовано: 25 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

EPSS

Процентиль: 26%
0.00093
Низкий

7.1 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.1
nvd
почти 4 года назад

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

EPSS

Процентиль: 26%
0.00093
Низкий

7.1 High

CVSS3

Дефекты

CWE-611