Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfx9-vc4c-6rwm

Опубликовано: 21 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

EPSS

Процентиль: 62%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

EPSS

Процентиль: 62%
0.00431
Низкий

7.5 High

CVSS3

Дефекты

CWE-611