PT-2023-19465 · Urule · Urule
Idam0N
·
Published
2023-02-24
·
Updated
2023-03-06
·
CVE-2023-24189
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
urule version 2.1.7
Description
An XML External Entity (XXE) issue allows attackers to execute arbitrary code by uploading a crafted XML file to the "/urule/common/saveFile" API endpoint. This is achieved by exploiting the
saveFile functionality, potentially allowing for unauthorized access and code execution.Recommendations
For urule version 2.1.7, consider disabling the
saveFile functionality or restricting access to the "/urule/common/saveFile" API endpoint until a patch is available. Avoid using this endpoint with untrusted or unvalidated XML files to minimize the risk of exploitation.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Urule