PT-2019-9935 · Prince · Princexml

Published

2019-01-29

·

Updated

2019-02-21

·

CVE-2018-19858

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrinceXML versions 10 and below
Description The issue allows an attacker to gain file-read access and perform Server-Side Request Forgery (SSRF) attacks by exploiting the lack of protection against external entities in PrinceXML. This can be achieved by passing HTML that references an XML file, which PrinceXML will then fetch and parse.
Recommendations For PrinceXML versions 10 and below, consider disabling the parsing of external entities as a temporary workaround until a patch is available. Restrict access to sensitive files and minimize the risk of exploitation by limiting the use of PrinceXML for parsing untrusted input.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19858

Affected Products

Princexml