PT-2018-12542 · Ocs · Ocs Inventory Ng

Juan Manuel Fernandez

·

Publicado

2018-08-03

·

Atualizado

2018-10-01

·

CVE-2018-14473

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions OCS Inventory version 2.4.1
Description The issue is related to improper XML parsing configuration, which allows the use of external entities. This can be exploited by an attacker through a crafted HTTP request, potentially leading to information exfiltration or a Denial of Service.
Recommendations For OCS Inventory version 2.4.1, consider disabling the XML parsing functionality until a proper configuration or patch is available to prevent the exploitation of external entities.

Exploit

Correção

DoS

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14473

Produtos afetados

Ocs Inventory Ng