PT-2019-9935 · Prince · Princexml
Published
2019-01-29
·
Updated
2019-02-21
·
CVE-2018-19858
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PrinceXML versions 10 and below
Description
The issue allows an attacker to gain file-read access and perform Server-Side Request Forgery (SSRF) attacks by exploiting the lack of protection against external entities in PrinceXML. This can be achieved by passing HTML that references an XML file, which PrinceXML will then fetch and parse.
Recommendations
For PrinceXML versions 10 and below, consider disabling the parsing of external entities as a temporary workaround until a patch is available. Restrict access to sensitive files and minimize the risk of exploitation by limiting the use of PrinceXML for parsing untrusted input.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Princexml