VYPR
High severity7.2NVD Advisory· Published Dec 19, 2023· Updated Jun 17, 2026

CVE-2023-6280

CVE-2023-6280

Description

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • 52North/WPSllm-fuzzy12 versions
    <4.0.0-beta.11+ 11 more
    • (no CPE)range: <4.0.0-beta.11
    • cpe:2.3:a:52north:wps:*:*:*:*:*:*:*:*range: <4.0.0
    • cpe:2.3:a:52north:wps:4.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:52north:wps:4.0.0:beta9:*:*:*:*:*:*
  • 52North/52North WPSv5
    Range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.