PT-2019-11151 · Enghouse · Enghouse Cloud Contact Center Platform
David Herrero
·
Publicado
2019-05-14
·
Atualizado
2019-05-15
·
CVE-2018-8940
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Enghouse Cloud Contact Center Platform version 7.2.5
Description:
The issue allows an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file. This is related to the functionality for loading external XML files and parsing them in the ClientServiceConfigController.cs.
Recommendations:
For Enghouse Cloud Contact Center Platform version 7.2.5, consider restricting access to the XML file upload functionality to prevent malicious file uploads until a patch is available. As a temporary workaround, avoid using the URL parameter that references external XML files in the application.
Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Enghouse Cloud Contact Center Platform