Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwqq-pcg2-pphr

Опубликовано: 30 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

EPSS

Процентиль: 38%
0.00447
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

EPSS

Процентиль: 38%
0.00447
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-611