VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 24 of 67
  • CVE-2024-3969HigMay 28, 2024
    risk 0.51cvss 7.8epss 0.01

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

  • CVE-2024-3486HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

  • CVE-2023-24187HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

  • CVE-2022-45588HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud…

  • CVE-2022-27873HigJul 29, 2022
    risk 0.51cvss 7.8epss 0.00

    An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage…

  • CVE-2021-46365HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

  • CVE-2022-21220HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-30201HigJul 9, 2021
    risk 0.51cvss 7.5epss 0.25

    The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Detailed description Given the following request: ``` POST /vsaWS/KaseyaWS.asmx…

  • CVE-2014-5238HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.02

    XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.

  • CVE-2019-8086HigOct 25, 2019
    risk 0.51cvss 7.5epss 0.23

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2018-18980HigNov 6, 2018
    risk 0.51cvss 7.5epss 0.25

    An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local…

  • CVE-2016-9487HigJul 13, 2018
    risk 0.51cvss 7.8epss 0.01

    EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit this behavior to read arbitrary files, or have the victim execute arbitrary…

  • CVE-2018-1000548HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability…

  • CVE-2018-1000546HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.03

    Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game…

  • CVE-2018-1000542HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.03

    netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD…

  • CVE-2018-1000540HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This…

  • CVE-2018-1247HigMay 8, 2018
    risk 0.51cvss 7.1epss 0.16

    RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted…

  • CVE-2017-1000498HigJan 3, 2018
    risk 0.51cvss 7.8epss 0.02

    AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

  • CVE-2016-5002HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.08

    XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.

  • CVE-2016-4434HigSep 30, 2017
    risk 0.51cvss 7.8epss 0.03

    Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a…