Critical severity10.0OSV Advisory· Published Dec 20, 2018· Updated Jun 17, 2026
CVE-2018-1000837
CVE-2018-1000837
Description
UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
40.9, 1.0, 1.4.0, …+ 1 more
- (no CPE)range: 0.9, 1.0, 1.4.0, …
- (no CPE)range: <=8.0.0
- Range: <=8.0.0
Patches
Vulnerability mechanics
References
2- 0dd.zone/2018/10/28/uml-designer-XXE/nvdIssue TrackingThird Party Advisory
- github.com/ObeoNetwork/UML-Designer/issues/1035nvdThird Party Advisory
News mentions
0No linked articles in our index yet.