Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:42250
HistoryAug 06, 2023 - 12:57 p.m.

XML External Entity (XXE)

2023-08-0612:57:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
xml external entity
php
uris
inaccurate output
security vulnerability

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

EPSS

0.001

Percentile

44.4%

php81 is vulnerable to XML External Entities (XXE). The program handles XML documents that include URIs that resolve to external resources, resulting in inaccurate output and posing problems for the end product.

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

EPSS

0.001

Percentile

44.4%