Описание
An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:focalscope:focalscope:2416:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02045
Низкий
9.4 Critical
CVSS3
9.4 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 9.4
github
больше 3 лет назад
An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.
EPSS
Процентиль: 83%
0.02045
Низкий
9.4 Critical
CVSS3
9.4 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-611