Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.
References
Link | Resource |
---|---|
https://github.com/osmandapp/Osmand/issues/8711 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-03-26 17:15
Updated : 2020-03-31 06:58
NVD link : CVE-2020-10993
Mitre link : CVE-2020-10993
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
osmand
- osmand