PT-2025-21224 · Peergos · Peergos

Titan Team

·

Published

2025-05-14

·

Updated

2025-05-14

·

CVE-2025-4639

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Peergos versions through 1.1.0
Description: The issue is related to an improper restriction of XML external entity reference in the getDocumentBuilder() method of the WebDav servlet in Peergos. This allows for potential exploitation.
Recommendations: For Peergos versions through 1.1.0, update to a version that includes a fix for the improper restriction of XML external entity reference in the getDocumentBuilder() method of the WebDav servlet. As a temporary workaround, consider restricting access to the WebDav servlet until a patch is available.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-4639

Affected Products

Peergos