PT-2023-13658 · Güralp · Güralp Man-Eam-0003

CVE-2022-38840

·

Publicado

2023-04-16

·

Atualizado

2023-04-25

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Güralp MAN-EAM-0003 version 3.2.4
Description The issue is related to an XML External Entity (XXE) problem via XML file upload, which can lead to local file disclosure. This occurs in the cgi-bin/xmlstatus.cgi component.
Recommendations For Güralp MAN-EAM-0003 version 3.2.4, consider disabling the XML file upload feature in cgi-bin/xmlstatus.cgi until a patch is available to prevent local file disclosure.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-38840

Produtos afetados

Güralp Man-Eam-0003