VYPR
Unrated severityNVD Advisory· Published Dec 19, 2023· Updated Aug 2, 2024

XML External Entity Reference on 52North WPS

CVE-2023-6280

Description

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An XXE vulnerability in 52North WPS before 4.0.0-beta.11 allows file retrieval and internal network probing.

Vulnerability

CVE-2023-6280 is an XML External Entity (XXE) vulnerability in the WebProcessingService servlet of 52North WPS versions prior to 4.0.0-beta.11. The product is at the end of its life cycle [1]. The servlet processes XML input without disabling external entity resolution, allowing an attacker to inject a malicious XML payload that references external entities.

Exploitation

An unauthenticated attacker can send a crafted XML request to the WebProcessingService endpoint. No privileged access or user interaction is required. By including an external entity definition pointing to a local file (e.g., file:///etc/passwd) or an internal HTTP resource, the server will resolve the entity and include its contents in the response. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L) confirms the attack is network-based with low complexity [1].

Impact

Successful exploitation allows the attacker to read arbitrary files from the server's file system and to make HTTP requests to internal network hosts, potentially enumerating services or extracting sensitive information. The impact is limited in terms of direct data loss (confidentiality) but can serve as a foothold for further attacks. The product is end-of-life, so no security updates are available [1].

Mitigation

52North WPS is end-of-life, and no patched version exists [1]. Users should migrate to an alternative WPS implementation that is actively maintained. If migration is not immediately possible, network segmentation and strict input validation on the WebProcessingService endpoint may reduce risk, but these are not a complete fix. No official fix or workaround is provided by the vendor.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • 52North/WPSllm-create
    Range: <4.0.0-beta.11
  • 52North/52North WPSv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.