PT-2022-10219 · Unknown · Mashzone Nextgen

Marcos Díaz

·

Published

2022-03-30

·

Updated

2022-04-05

·

CVE-2021-33208

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MashZone NextGen versions through 10.7 GA
Description The issue allows XXE attacks via a malicious XML configuration file, specifically through the "Register an Ehcache Configuration File" admin feature.
Recommendations For MashZone NextGen versions through 10.7 GA, consider disabling the "Register an Ehcache Configuration File" admin feature until a patch is available to prevent XXE attacks.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33208

Affected Products

Mashzone Nextgen