VYPR
Critical severity9.1OSV Advisory· Published Aug 4, 2018· Updated Jun 17, 2026

CVE-2018-14473

CVE-2018-14473

Description

OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • 2.2, 2.2.1, 2.2RC1, …+ 1 more
    • (no CPE)range: 2.2, 2.2.1, 2.2RC1, …
    • cpe:2.3:a:ocsinventory-ng:ocsinventory_ng:2.4.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.