VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 28 of 67
  • CVE-2024-45490HigAug 30, 2024
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2024-36827HigJun 7, 2024
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

  • CVE-2023-51591HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Voltronic Power ViewPower Pro. Authentication is not required…

  • CVE-2023-40507HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-40506HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-40503HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this…

  • CVE-2023-22274HigNov 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

  • CVE-2023-46590HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of…

  • CVE-2023-38343HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side…

  • CVE-2023-40239HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.00

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…

  • CVE-2020-26710HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2020-26709HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2020-26708HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2023-27527HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.

  • CVE-2023-28680HigApr 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-22624HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

  • CVE-2023-23595HigJan 15, 2023
    risk 0.49cvss 7.5epss 0.01

    BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are…

  • CVE-2022-42745HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.01

    CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

  • CVE-2022-40705HigSep 22, 2022
    risk 0.49cvss 7.5epss 0.01

    An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also…

  • CVE-2022-1700HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security…