Логотип exploitDog
bind:CVE-2023-38343
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38343

Количество 2

Количество 2

nvd логотип

CVE-2023-38343

больше 2 лет назад

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rfx9-vc4c-6rwm

больше 2 лет назад

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38343

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-rfx9-vc4c-6rwm

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу