Description
oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue.
References (4)
Core 4
Core References
Patch x_refsource_confirm
http://wiki.orbeon.com/forms/doc/developer-guide/release-notes/39
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/47362
Exploit x_refsource_misc
http://www.stratsec.net/Research/Advisories/Orbeon-Forms-XML-Entity-Dereferencing-%28SS-2011-004
Patch x_refsource_confirm
https://github.com/orbeon/orbeon-forms/commit/aba6681660f65af7f1676434da68c10298c30200
Scores
EPSS
0.0218
EPSS Percentile
80.5%
Details
CWE
CWE-264
Status
published
Products (14)
orbeon/forms
1.5
orbeon/forms
2.0
orbeon/forms
2.1
orbeon/forms
2.2
orbeon/forms
2.5
orbeon/forms
2.6
orbeon/forms
2.7
orbeon/forms
2.8
orbeon/forms
3.0
orbeon/forms
3.5
... and 4 more
Published
Apr 27, 2011
Tracked Since
Feb 18, 2026