7.5

CVE-2023-6280

XML External Entity Reference on 52North WPS

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
52north ≫ Wps Version < 4.0.0
52north ≫ Wps Version 4.0.0 Update beta1
52north ≫ Wps Version 4.0.0 Update beta10
52north ≫ Wps Version 4.0.0 Update beta2
52north ≫ Wps Version 4.0.0 Update beta3
52north ≫ Wps Version 4.0.0 Update beta4
52north ≫ Wps Version 4.0.0 Update beta5
52north ≫ Wps Version 4.0.0 Update beta6
52north ≫ Wps Version 4.0.0 Update beta7
52north ≫ Wps Version 4.0.0 Update beta8
52north ≫ Wps Version 4.0.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cve-coordination@incibe.es 7.2 3.9 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://www.incibe.es/en/incibe-cert/notices/aviso/xml-external-entity-reference-52north-wps
Third Party Advisory