PT-2019-11151 · Enghouse · Enghouse Cloud Contact Center Platform

David Herrero

·

Published

2019-05-14

·

Updated

2019-05-15

·

CVE-2018-8940

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Enghouse Cloud Contact Center Platform version 7.2.5
Description: The issue allows an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file. This is related to the functionality for loading external XML files and parsing them in the ClientServiceConfigController.cs.
Recommendations: For Enghouse Cloud Contact Center Platform version 7.2.5, consider restricting access to the XML file upload functionality to prevent malicious file uploads until a patch is available. As a temporary workaround, avoid using the URL parameter that references external XML files in the application.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8940

Affected Products

Enghouse Cloud Contact Center Platform