PT-2024-19283 · Terminalfour · Terminalfour

Published

2024-08-15

·

Updated

2024-08-19

·

CVE-2024-22219

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Terminalfour versions 8.0.0001 through 8.3.18 XML JDBC versions up to 1.0.4
Description The issue allows authenticated users to submit malicious XML via unspecified features, which could lead to various actions such as accessing the underlying server, remote code execution (RCE), or performing Server-Side Request Forgery (SSRF) attacks.
Recommendations For Terminalfour versions 8.0.0001 through 8.3.18, consider disabling the XML submission feature until a patch is available. For XML JDBC versions up to 1.0.4, restrict access to the XML JDBC module to minimize the risk of exploitation. As a temporary workaround, avoid using the unspecified features that allow malicious XML submission until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-22219

Affected Products

Terminalfour