LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.
References
Link | Resource |
---|---|
https://github.com/arnobl/latexdraw/issues/10 | Exploit Issue Tracking Patch Third Party Advisory |
https://0dd.zone/2018/08/05/LatexDraw-XXE/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-08-20 12:31
Updated : 2019-09-26 08:19
NVD link : CVE-2018-1000639
Mitre link : CVE-2018-1000639
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
latexdraw_project
- latexdraw