PT-2019-11509 · Jeesite · Jeesite

Publicado

2019-07-23

·

Atualizado

2019-08-05

·

CVE-2019-1010202

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jeesite versions prior to 4.0
Description: The issue affects the convertToModel() function in the ActProcessService.java file, allowing for sensitive information disclosure through an XML External Entity (XXE) attack. This can be exploited by uploading a specially crafted XML file, requiring network connectivity and authentication.
Recommendations: For versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider disabling the convertToModel() function until a patch is available. Restrict access to the ActProcessService.java module to minimize the risk of exploitation. Avoid uploading XML files from untrusted sources to the affected API endpoint until the issue is resolved.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1010202

Produtos afetados

Jeesite