Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r43h-pvqh-qq63

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

EPSS

Процентиль: 60%
0.00394
Низкий

7.2 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.2
nvd
почти 6 лет назад

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploaded file.

EPSS

Процентиль: 60%
0.00394
Низкий

7.2 High

CVSS3

Дефекты

CWE-611