← voltar
CVE-2023-2806mediumexploração observadaCWE-611

Weaver e-cology API RequestInfoByXml xml external entity reference

35Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Attendcvss 5.5epss 1.0%
da publicação à arma
Publicada no NVD19 de mai.
VulnCheck+984d
probabilidade de exploração
1.0%top 41% das CVEs
exploração observada
simVulnCheck
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Produtos afetados
Weaver · e-cology