CVE-2018-10832

MEDIUM

Modbuspal - XXE

Title source: rule
STIX 2.1

Description

ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

Exploits (1)

exploitdb WORKING POC
by Trent Gordon · textwebappsjava
https://www.exploit-db.com/exploits/44607

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44607/

Scores

CVSS v3 5.5
EPSS 0.0175
EPSS Percentile 82.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
modbuspal_project/modbuspal 1.6 b
Published May 11, 2018
Tracked Since Feb 18, 2026