Описание
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:charlesproxy:charles:4.2.7:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00402
Низкий
8.6 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 8.6
github
больше 3 лет назад
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
EPSS
Процентиль: 60%
0.00402
Низкий
8.6 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611