PT-2019-11151 · Enghouse · Enghouse Cloud Contact Center Platform
David Herrero
·
Published
2019-05-14
·
Updated
2019-05-15
·
CVE-2018-8940
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Enghouse Cloud Contact Center Platform version 7.2.5
Description:
The issue allows an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file. This is related to the functionality for loading external XML files and parsing them in the ClientServiceConfigController.cs.
Recommendations:
For Enghouse Cloud Contact Center Platform version 7.2.5, consider restricting access to the XML file upload functionality to prevent malicious file uploads until a patch is available. As a temporary workaround, avoid using the URL parameter that references external XML files in the application.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enghouse Cloud Contact Center Platform