An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.
References
Link | Resource |
---|---|
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0559 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-08-01 13:29
Updated : 2023-02-03 05:56
NVD link : CVE-2018-3881
Mitre link : CVE-2018-3881
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
focalscope
- focalscope