PT-2025-30070 · Unknown · Agorum Core Open

Dr

+5

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-52162

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions agorum core open versions 11.9.2 and 11.10.1
Description The software contains an XML External Entity (XXE) issue via the RSSReader endpoint. Attackers can potentially access sensitive data by providing a crafted XML input.
Recommendations For agorum core open version 11.9.2, implement input validation and sanitization for XML data processed by the RSSReader endpoint. For agorum core open version 11.10.1, implement input validation and sanitization for XML data processed by the RSSReader endpoint.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-52162

Affected Products

Agorum Core Open