CWE-611
Improper Restriction of XML External Entity Reference
Description
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-221
CVEs mapped to this weakness (1,331)
page 5 of 67| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-18705 | Cri | 0.64 | 9.8 | 0.03 | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'. | ||
| CVE-2020-18703 | Cri | 0.64 | 9.8 | 0.03 | Aug 16, 2021 | XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'. | ||
| CVE-2021-35066 | Cri | 0.64 | 9.8 | 0.01 | Jun 21, 2021 | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. | ||
| CVE-2021-1628 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2021 | MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021. | ||
| CVE-2021-26703 | Cri | 0.64 | 9.8 | 0.04 | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. | ||
| CVE-2020-35604 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. | ||
| CVE-2020-25215 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2020 | yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. | ||
| CVE-2020-25257 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2020 | An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files. | ||
| CVE-2020-24379 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2020 | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. | ||
| CVE-2020-12684 | Cri | 0.64 | 9.8 | 0.01 | Jul 15, 2020 | XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser. | ||
| CVE-2020-11586 | Cri | 0.64 | 9.8 | 0.01 | Apr 6, 2020 | An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data. | ||
| CVE-2020-10992 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2020 | Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. | ||
| CVE-2020-10991 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2020 | Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java | ||
| CVE-2020-9352 | Cri | 0.64 | 9.8 | 0.02 | Feb 23, 2020 | An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states… | ||
| CVE-2014-2052 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2020 | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. | ||
| CVE-2018-20687 | Cri | 0.64 | 9.8 | 0.03 | Nov 18, 2019 | An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML… | ||
| CVE-2019-1010268 | Cri | 0.64 | 9.8 | 0.06 | Jul 18, 2019 | Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance:… | ||
| CVE-2019-12924 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host… | ||
| CVE-2018-15506 | Cri | 0.64 | 9.8 | 0.05 | Jun 19, 2019 | In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same… | ||
| CVE-2018-18471 | Cri | 0.64 | 9.8 | 0.08 | Jun 19, 2019 | /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of… |
- risk 0.64cvss 9.8epss 0.03
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
- risk 0.64cvss 9.8epss 0.03
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
- risk 0.64cvss 9.8epss 0.01
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
- risk 0.64cvss 9.8epss 0.01
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.
- risk 0.64cvss 9.8epss 0.04
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
- risk 0.64cvss 9.8epss 0.02
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
- risk 0.64cvss 9.8epss 0.01
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks for read/write access to arbitrary files.
- risk 0.64cvss 9.8epss 0.03
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- risk 0.64cvss 9.8epss 0.01
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
- risk 0.64cvss 9.8epss 0.01
An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.
- risk 0.64cvss 9.8epss 0.01
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
- risk 0.64cvss 9.8epss 0.01
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states…
- risk 0.64cvss 9.8epss 0.02
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
- risk 0.64cvss 9.8epss 0.03
An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML…
- risk 0.64cvss 9.8epss 0.06
Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance:…
- risk 0.64cvss 9.8epss 0.01
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host…
- risk 0.64cvss 9.8epss 0.05
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same…
- risk 0.64cvss 9.8epss 0.08
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of…