High severity7.8OSV Advisory· Published Jun 26, 2018· Updated Jun 17, 2026
CVE-2018-1000542
CVE-2018-1000542
Description
netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31.0.0, 1.0.0-beta, 1.1.0, …+ 1 more
- (no CPE)range: 1.0.0, 1.0.0-beta, 1.1.0, …
- (no CPE)range: <=1.4.3
- cpe:2.3:a:netbeans-mmd-plugin_project:netbeans-mmd-plugin:1.4.3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- 0dd.zone/2018/06/02/Netbeans-MMD-Plugin-XXE/nvdExploitThird Party Advisory
- github.com/raydac/netbeans-mmd-plugin/issues/45nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.