High severity7.8OSV Advisory· Published Jun 26, 2018· Updated Jun 17, 2026
CVE-2018-1000546
CVE-2018-1000546
Description
Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=1.9.0.0.10291+ 2 more
- (no CPE)range: <=1.9.0.0.10291
- (no CPE)range: 1.8.0.10.1006, 1.8.0.10.1007, 1.8.0.10.1009, …
- cpe:2.3:a:triplea-game:triplea:*:*:*:*:*:*:*:*range: <=1.9.0.0.10291
Patches
Vulnerability mechanics
References
2- 0dd.zone/2018/05/31/TripleA-XXE/nvdExploitThird Party Advisory
- github.com/triplea-game/triplea/issues/3442nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.