PT-2021-10423 · S Cms · S-Cms
Published
2021-10-14
·
Updated
2021-10-20
·
CVE-2020-19954
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
S-CMS version 3.0
Description:
An XML External Entity (XXE) issue was found in the "api/notify.php" endpoint, allowing attackers to read arbitrary files. This could potentially lead to sensitive information disclosure.
Recommendations:
For S-CMS version 3.0, consider disabling access to the /api/notify.php endpoint until a fix is available to prevent exploitation of the XXE issue.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
S-Cms