Описание
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.12.0 (включая)
cpe:2.3:a:apereo:bw-calendar-engine:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00292
Низкий
9 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 9
github
около 7 лет назад
XML External Entity (XXE) vulnerability in bw-calendar-engine
EPSS
Процентиль: 52%
0.00292
Низкий
9 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-611