The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/533894 | Exploit US Government Resource |
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats | |
http://www.securityfocus.com/bid/63431 | Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-11-02 12:55
Updated : 2013-11-21 10:29
NVD link : CVE-2013-3617
Mitre link : CVE-2013-3617
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
openbravo
- openbravo_erp