CVE-2024-29010

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-01 18:15

Updated : 2024-05-01 19:50


NVD link : CVE-2024-29010

Mitre link : CVE-2024-29010

CVE.ORG link : CVE-2024-29010


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference