High severity7.5NVD Advisory· Published Oct 29, 2019· Updated Jun 17, 2026
CVE-2019-9757
CVE-2019-9757
Description
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:labkey:labkey_server:19.1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:labkey:labkey_server:19.1.0:*:*:*:*:*:*:*
- (no CPE)range: =19.1.0
- LabKey/LabKey Serverdescription
Patches
Vulnerability mechanics
References
2- github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-9757nvdExploit
- rhinosecuritylabs.com/application-security/labkey-server-vulnerabilities-to-rcenvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.