VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,372)

page 31 of 69
  • CVE-2021-29447HigApr 15, 2021
    risk 0.49cvss 7.1epss 0.86

    Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful…

  • CVE-2020-6590HigApr 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

  • CVE-2021-28110HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.01

    /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

  • CVE-2021-27184HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.02

    Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered…

  • CVE-2020-24454HigNov 12, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via…

  • CVE-2020-25186HigOct 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.

  • CVE-2020-4643HigSep 21, 2020
    risk 0.49cvss 7.5epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.

  • CVE-2020-14029HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.

  • CVE-2020-5602HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX…

  • CVE-2020-14940HigJun 23, 2020
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gpx) and GP7 (.gp) tablature files.

  • CVE-2020-2012HigMay 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panorama management interface to read arbitrary files on the system. This issue…

  • CVE-2020-10629HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.

  • CVE-2019-20191HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Oxygen XML Editor 21.1.1 allows XXE to read any file.

  • CVE-2020-9044HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.01

    XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys…

  • CVE-2020-2108HigJan 29, 2020
    risk 0.49cvss 7.6epss 0.01

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.

  • CVE-2015-1811HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.

  • CVE-2015-1809HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

  • CVE-2019-18412HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    JetBrains IDETalk plugin before version 193.4099.10 allows XXE

  • CVE-2019-19998HigDec 26, 2019
    risk 0.49cvss 7.5epss 0.01

    Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

  • CVE-2019-18227HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.03

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.