CVE-2017-1000496

HIGH

Commsy 9.0.0 - XML External Entity Injection in Configuration Import

Title source: llm
STIX 2.1

Description

Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/commsy/commsy/issues/2

Scores

CVSS v3 8.8
EPSS 0.0174
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (1)
commsy/commsy 9.0.0
Published Jan 03, 2018
Tracked Since Feb 18, 2026