High severity7.2NVD Advisory· Published Mar 20, 2018· Updated Jun 17, 2026
CVE-2018-1321
CVE-2018-1321
Description
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.syncope:syncope-coreMaven | < 1.2.11 | 1.2.11 |
org.apache.syncope:syncope-coreMaven | >= 2.0.0, < 2.0.8 | 2.0.8 |
Affected products
2- Apache Software Foundation/Apache Syncopev5Range: Releases prior to 1.2.11, Releases prior to 2.0.8
Patches
Vulnerability mechanics
References
8- syncope.apache.org/security.htmlnvdMitigationVendor AdvisoryWEB
- www.securityfocus.com/bid/103508nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-xgc9-9w4v-h33hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1321ghsaADVISORY
- www.exploit-db.com/exploits/45400/nvdThird Party AdvisoryVDB Entry
- github.com/apache/syncope/commit/726231fbf7b817bd2a9467171dcb1c0087c75bcghsaWEB
- github.com/apache/syncope/commit/ad31479c1c543ac7d26b8c882aa14f6c00c1fd0ghsaWEB
- www.exploit-db.com/exploits/45400ghsaWEB
News mentions
0No linked articles in our index yet.