PT-2026-7690 · Top Password · Msn Password Recovery

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2020-37192

CVSS v3.1

6.2

Medium

AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-37192

Affected Products

Msn Password Recovery