Описание
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:s-cms:s-cms:3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00439
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
github
больше 3 лет назад
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
EPSS
Процентиль: 63%
0.00439
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-611