CVE-2018-10077

MEDIUM

Geist WatchDog Console 3.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.

Exploits (1)

exploitdb WORKING POC
by bzyo · textwebappsxml
https://www.exploit-db.com/exploits/44493

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44493/

Scores

CVSS v3 4.9
EPSS 0.1411
EPSS Percentile 94.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
vertiv/watchdog_console 3.2.2
Published Apr 20, 2018
Tracked Since Feb 18, 2026