PT-2025-21224 · Peergos · Peergos
Titan Team
·
Published
2025-05-14
·
Updated
2025-05-14
·
CVE-2025-4639
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Peergos versions through 1.1.0
Description:
The issue is related to an improper restriction of XML external entity reference in the getDocumentBuilder() method of the WebDav servlet in Peergos. This allows for potential exploitation.
Recommendations:
For Peergos versions through 1.1.0, update to a version that includes a fix for the improper restriction of XML external entity reference in the getDocumentBuilder() method of the WebDav servlet. As a temporary workaround, consider restricting access to the WebDav servlet until a patch is available.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peergos