Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38016
HistoryNov 16, 2022 - 5:14 a.m.

XML External Entity (XXE)

2022-11-1605:14:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
xml external entity
concrete cms
sanitizer.php
ip disclosure

0.002 Low

EPSS

Percentile

54.6%

Concrete CMS is vulnerable to XML external entity. The vulnerability exists in dataToXml function in Sanitizer.php, which allows an attacker to inject and execute malicious code into the system due to improper sanitization of SVGs, leading to IP disclosure.

0.002 Low

EPSS

Percentile

54.6%

Related for VERACODE:38016