Логотип exploitDog
bind:CVE-2025-24521
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-24521

Количество 2

Количество 2

nvd логотип

CVE-2025-24521

11 месяцев назад

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-m8gj-rhh9-783q

11 месяцев назад

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25.

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-24521

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25.

CVSS3: 4.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-m8gj-rhh9-783q

External XML entity injection allows arbitrary download of files. The score without least privilege principle violation is as calculated below. In combination with other issues it may facilitate further compromise of the device. Remediation in Version 6.8.0, release date: 01-Mar-25.

CVSS3: 4.9
0%
Низкий
11 месяцев назад

Уязвимостей на страницу