PT-2018-6728 · Jgraph · Mxgraph
Lehanhua
·
Published
2018-02-24
·
Updated
2024-06-15
·
CVE-2017-18197
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
mxGraph versions prior to 3.7.6
Description:
The issue concerns a missing configuration in the SAXParserFactory instance within the convert() function of mxGraphViewImageReader.java, which makes it susceptible to XML External Entity (XXE) attacks. This is demonstrated by the /ServerView endpoint.
Recommendations:
For versions prior to 3.7.6, update to version 3.7.6 or later to resolve the issue. As a temporary workaround, consider configuring the SAXParserFactory instance to prevent XXE attacks by setting the necessary flags.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mxgraph