PT-2024-34443 · Unknown · Worldserver
Nikita Hrab
·
Published
2024-11-18
·
Updated
2025-10-20
·
CVE-2024-50848
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
WorldServer version 11.8.2
Description:
The issue is related to an XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities. This vulnerability can be exploited by supplying a crafted .tmx file, allowing access to sensitive information and execution of arbitrary commands.
Recommendations:
For WorldServer version 11.8.2, consider disabling the Import object and Translation Memory import functionalities until a patch is available to prevent exploitation of the XXE vulnerability. Restrict access to these functionalities to minimize the risk of sensitive information disclosure and arbitrary command execution.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Worldserver