Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-3543
HistoryJul 29, 2014 - 12:00 a.m.

CVE-2014-3543

2014-07-2900:00:00
ubuntu.com
ubuntu.com
18

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.3%

mod/imscp/locallib.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x
before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote
attackers to read arbitrary files via a package with a manifest file
containing an XML external entity declaration in conjunction with an entity
reference, related to an XML External Entity (XXE) issue affecting IMSCP
resources and the IMSCC format.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.3%