VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 29 of 69
  • CVE-2023-38343HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side…

  • CVE-2023-40239HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…

  • CVE-2020-26710HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2020-26709HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2020-26708HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.

  • CVE-2023-27527HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.

  • CVE-2023-28680HigApr 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-22624HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

  • CVE-2023-23595HigJan 15, 2023
    risk 0.49cvss 7.5epss 0.01

    BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are…

  • CVE-2022-42745HigNov 3, 2022
    risk 0.49cvss 7.5epss 0.01

    CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

  • CVE-2022-40705HigSep 22, 2022
    risk 0.49cvss 7.5epss 0.02

    An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also…

  • CVE-2022-1700HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security…

  • CVE-2022-37189HigSep 7, 2022
    risk 0.49cvss 7.5epss 0.01

    DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.

  • CVE-2022-0217HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.05

    It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition,…

  • CVE-2020-21641HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.04

    Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

  • CVE-2022-1704HigAug 5, 2022
    risk 0.49cvss 7.6epss 0.01

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

  • CVE-2022-32458HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.

  • CVE-2022-35168HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative.

  • CVE-2021-40510HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

  • CVE-2022-32285HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML…