VYPR

CWE-611

Improper Restriction of XML External Entity Reference

BaseDraft

Description

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-221

CVEs mapped to this weakness (1,331)

page 5 of 67
  • CVE-2020-18705CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.03

    XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.

  • CVE-2020-18703CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.03

    XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.

  • CVE-2021-35066CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.01

    An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

  • CVE-2021-1628CriMar 26, 2021
    risk 0.64cvss 9.8epss 0.01

    MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.

  • CVE-2021-26703CriMar 1, 2021
    risk 0.64cvss 9.8epss 0.04

    EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.

  • CVE-2020-35604CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.

  • CVE-2020-25215CriSep 17, 2020
    risk 0.64cvss 9.8epss 0.01

    yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.

  • CVE-2020-25257CriSep 11, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.

  • CVE-2020-24379CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.03

    WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

  • CVE-2020-12684CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.01

    XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.

  • CVE-2020-11586CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.01

    An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.

  • CVE-2020-10992CriMar 27, 2020
    risk 0.64cvss 9.8epss 0.01

    Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.

  • CVE-2020-10991CriMar 27, 2020
    risk 0.64cvss 9.8epss 0.01

    Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

  • CVE-2020-9352CriFeb 23, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states…

  • CVE-2014-2052CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.02

    Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

  • CVE-2018-20687CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.03

    An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML…

  • CVE-2019-1010268CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.06

    Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance:…

  • CVE-2019-12924CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.01

    MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host…

  • CVE-2018-15506CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.05

    In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same…

  • CVE-2018-18471CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.08

    /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of…