← Back

CVE-2023-6280

nvd nist
Published: Dec 19, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

Affected (11)

Products: 52north: Wps
1 product
Wps
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
52north
Before 4.0.0
Version 4.0.0 beta10
Version 4.0.0 beta1
Version 4.0.0 beta2
Version 4.0.0 beta3
Version 4.0.0 beta4
Version 4.0.0 beta5
Version 4.0.0 beta6
Version 4.0.0 beta7
Version 4.0.0 beta8
Version 4.0.0 beta9

References (2)

Timeline

No history available yet.