PT-2019-12351 · Nopcommerce · Nopcommerce

Andreimaz

·

Publicado

2019-04-25

·

Atualizado

2019-05-01

·

CVE-2019-11519

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions nopCommerce versions prior to 4.10
Description The issue concerns an XXE vulnerability in the LocalizationService.cs file. This vulnerability can be exploited via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen, allowing for potential XML eXternal Entity (XXE) attacks.
Recommendations For versions prior to 4.10, as a temporary workaround, consider disabling the XML file upload functionality in the "Configurations -> Languages -> Edit Language -> Import Resources" section until a patch is available. Restrict access to the LocalizationService.cs file to minimize the risk of exploitation. Avoid using the XML upload feature in the affected screen until the issue is resolved.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11519

Produtos afetados

Nopcommerce