Логотип exploitDog
bind:CVE-2018-19858
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-19858

Количество 2

Количество 2

nvd логотип

CVE-2018-19858

около 7 лет назад

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-67m6-wgh8-4vh7

больше 3 лет назад

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-19858

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

CVSS3: 8.6
0%
Низкий
около 7 лет назад
github логотип
GHSA-67m6-wgh8-4vh7

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

CVSS3: 8.6
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу