High severity8.8NVD Advisory· Published Dec 18, 2022· Updated Jun 17, 2026
CVE-2022-47514
CVE-2022-47514
Description
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:xml-rpc.net_project:xml-rpc.net:*:*:*:*:*:*:*:*Range: <2.5.0
- XML-RPC.NET/XML-RPC.NETdescription
- Range: <2.5.0
- Range: <2.5.0
Patches
Vulnerability mechanics
References
1- papercutsoftware.github.io/XML-RPC.NET/download.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.