Описание
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sdl:web_content_manager:8.5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05789
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
EPSS
Процентиль: 90%
0.05789
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-611