VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 43 of 67
  • CVE-2023-51602MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…

  • CVE-2023-51601MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…

  • CVE-2023-51600MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to…

  • CVE-2023-42035MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Visualware MyConnection Server. Authentication is not required…

  • CVE-2023-39472MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automation Ignition. Authentication is required…

  • CVE-2023-52239MedFeb 6, 2024
    risk 0.42cvss 6.5epss 0.00

    The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

  • CVE-2024-23525MedJan 18, 2024
    risk 0.42cvss 6.5epss 0.01

    The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

  • CVE-2023-45139HigJan 10, 2024
    risk 0.42cvss 7.5epss 0.01

    fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed.…

  • CVE-2022-34832MedOct 27, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.

  • CVE-2023-41932MedSep 6, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file…

  • CVE-2023-35389MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

  • CVE-2023-37942MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-34411HigJun 5, 2023
    risk 0.42cvss 7.5epss 0.01

    The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.

  • CVE-2023-28009MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2023-26058MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.00

    An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created…

  • CVE-2023-26057MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.00

    An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically…

  • CVE-2023-28684MedApr 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-26267MedFeb 21, 2023
    risk 0.42cvss 6.5epss 0.01

    php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.

  • CVE-2023-22832HigFeb 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that include the ExtractCCDAAttributes Processor are vulnerable to malicious XML documents that contain Document Type Declarations with…

  • CVE-2022-43430HigOct 19, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.