High severity7.5NVD Advisory· Published Aug 29, 2018· Updated Jun 17, 2026
CVE-2017-17762
CVE-2017-17762
Description
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:episerver:episerver:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:episerver:episerver:*:*:*:*:*:*:*:*range: <=7
- cpe:2.3:a:episerver:episerver:7:*:*:*:*:*:*:*
- cpe:2.3:a:episerver:episerver:7:patch_1:*:*:*:*:*:*
- cpe:2.3:a:episerver:episerver:7:patch_2:*:*:*:*:*:*
- cpe:2.3:a:episerver:episerver:7:patch_3:*:*:*:*:*:*
- cpe:2.3:a:episerver:episerver:7:patch_4:*:*:*:*:*:*
- (no CPE)range: <=7 patch 4
Patches
Vulnerability mechanics
References
2- gist.github.com/jonaslejon/5f92779848360a1a1e676af0795bd9aanvdExploitThird Party Advisory
- kryptera.se/sarbarhet-i-episerver/nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.