PT-2024-34443 · Unknown · Worldserver

Nikita Hrab

·

Published

2024-11-18

·

Updated

2025-10-20

·

CVE-2024-50848

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: WorldServer version 11.8.2
Description: The issue is related to an XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities. This vulnerability can be exploited by supplying a crafted .tmx file, allowing access to sensitive information and execution of arbitrary commands.
Recommendations: For WorldServer version 11.8.2, consider disabling the Import object and Translation Memory import functionalities until a patch is available to prevent exploitation of the XXE vulnerability. Restrict access to these functionalities to minimize the risk of sensitive information disclosure and arbitrary command execution.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-50848

Affected Products

Worldserver