CVE-2018-1000515

HIGH

ventrian News-Articles <NewsArticles.00.09.11 - XML External Entity

Title source: llm
STIX 2.1

Description

ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server..

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0135
EPSS Percentile 67.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
news-articles_project/news-articles 00.09.11
Published Jun 26, 2018
Tracked Since Feb 18, 2026