Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmmh-6g98-m869

Опубликовано: 10 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-611