Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27972
HistoryNov 24, 2020 - 5:49 a.m.

XML External Entity (XXE)

2020-11-2405:49:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
typo3
cms-core
xxe
rsswidget.php
vulnerability
libxml object

EPSS

0.001

Percentile

31.4%

typo3/cms-core is vulnerable to XML external entities (XXE). The vulnerability exists as the libxml object in getRssItems() of RssWidget.php does not disable external entities…

EPSS

0.001

Percentile

31.4%