An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/xml-external-entity-reference-52north-wps | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-12-19 15:15
Updated : 2024-05-17 02:33
NVD link : CVE-2023-6280
Mitre link : CVE-2023-6280
CVE.ORG link : CVE-2023-6280
JSON object : View
Products Affected
52north
- wps
CWE
CWE-611
Improper Restriction of XML External Entity Reference