Vulnerability Description
LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted XML file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Loboevolution Project | Loboevolution | < 0.99.3 |
Related Weaknesses (CWE)
References
- https://github.com/oswetto/LoboEvolution/issues/38ExploitThird Party Advisory
- https://github.com/oswetto/LoboEvolution/issues/38ExploitThird Party Advisory
FAQ
What is CVE-2018-1000540?
CVE-2018-1000540 is a vulnerability with a CVSS score of 7.8 (HIGH). LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosur...
How severe is CVE-2018-1000540?
CVE-2018-1000540 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000540?
Check the references section above for vendor advisories and patch information. Affected products include: Loboevolution Project Loboevolution.