Vulnerability Description
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Subsonic | Subsonic | 6.1.1 |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/SUBSONIC-XML-EXTERNAL-ENITITY.txtExploitThird Party Advisory
- http://packetstormsecurity.com/files/142795/Subsonic-6.1.1-XML-External-Entity-AExploitThird Party Advisory
- https://www.exploit-db.com/exploits/42119/
- http://hyp3rlinx.altervista.org/advisories/SUBSONIC-XML-EXTERNAL-ENITITY.txtExploitThird Party Advisory
- http://packetstormsecurity.com/files/142795/Subsonic-6.1.1-XML-External-Entity-AExploitThird Party Advisory
- https://www.exploit-db.com/exploits/42119/
FAQ
What is CVE-2017-9355?
CVE-2017-9355 is a vulnerability with a CVSS score of 7.4 (HIGH). XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist ...
How severe is CVE-2017-9355?
CVE-2017-9355 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9355?
Check the references section above for vendor advisories and patch information. Affected products include: Subsonic Subsonic.