PT-2019-11509 · Jeesite · Jeesite
Published
2019-07-23
·
Updated
2019-08-05
·
CVE-2019-1010202
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Jeesite versions prior to 4.0
Description:
The issue affects the convertToModel() function in the ActProcessService.java file, allowing for sensitive information disclosure through an XML External Entity (XXE) attack. This can be exploited by uploading a specially crafted XML file, requiring network connectivity and authentication.
Recommendations:
For versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider disabling the convertToModel() function until a patch is available. Restrict access to the ActProcessService.java module to minimize the risk of exploitation. Avoid uploading XML files from untrusted sources to the affected API endpoint until the issue is resolved.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jeesite