VYPR

CWE-91

XML Injection (aka Blind XPath Injection)

BaseDraft

Description

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Within XML, special elements could include reserved words or characters such as "<", ">", """, and "&", which could then be used to add new data or modify XML syntax.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-83

CVEs mapped to this weakness (138)

page 1 of 7
  • CVE-2020-0646CriKEVJan 14, 2020
    risk 0.87cvss 9.8epss 0.99

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

  • CVE-2023-43187CriSep 27, 2023
    risk 0.67cvss 9.8epss 0.45

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

  • CVE-2015-6970CriFeb 18, 2020
    risk 0.67cvss 9.8epss 0.05

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

  • CVE-2021-4140CriDec 22, 2022
    risk 0.65cvss 10.0epss 0.01

    It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2019-17626CriOct 16, 2019
    risk 0.65cvss 9.8epss 0.10

    ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

  • CVE-2024-51136CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.

  • CVE-2019-19450CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.04

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

  • CVE-2021-37154CriAug 25, 2021
    risk 0.64cvss 9.8epss 0.01

    In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 assertion.

  • CVE-2020-25216CriSep 17, 2020
    risk 0.64cvss 9.8epss 0.02

    yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesheet.

  • CVE-2020-11535CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code on a victim's server.

  • CVE-2013-4857CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

  • CVE-2019-14277CriJul 26, 2019
    risk 0.64cvss 9.8epss 0.07

    Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI…

  • CVE-2013-7429CriSep 14, 2017
    risk 0.64cvss 9.8epss 0.02

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

  • CVE-2023-46214HigNov 16, 2023
    risk 0.62cvss 8.0epss 0.89

    In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk…

  • CVE-2020-8479CriApr 29, 2020
    risk 0.61cvss 9.4epss 0.02

    For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+…

  • CVE-2023-27253HigMar 17, 2023
    risk 0.60cvss 8.8epss 0.90

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

  • CVE-2021-38948CriNov 2, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.

  • CVE-2021-36033CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.03

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

  • CVE-2021-36028CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.03

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability when saving a configurable product. An attacker with admin privileges can trigger a specially crafted script to achieve remote code…

  • CVE-2021-36022CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.03

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.