1mhr4b

2 exploits Active since Nov 2024
CVE-2024-50848 NOMISEC MEDIUM WRITEUP
RWS Worldserver - XXE
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
CVSS 6.5
CVE-2024-50849 NOMISEC MEDIUM WRITEUP
RWS Worldserver - XSS
A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.
CVSS 4.8