Critical severity9.1OSV Advisory· Published Aug 4, 2018· Updated Jun 17, 2026
CVE-2018-14473
CVE-2018-14473
Description
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22.2, 2.2.1, 2.2RC1, …+ 1 more
- (no CPE)range: 2.2, 2.2.1, 2.2RC1, …
- cpe:2.3:a:ocsinventory-ng:ocsinventory_ng:2.4.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.tarlogic.com/en/blog/vulnerabilities-in-ocs-inventory-2-4-1/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.