CVE-2018-1321

HIGH

Apache Syncope < 1.2.11 - Improper Input Validation

Title source: rule

Description

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

Exploits (1)

exploitdb WORKING POC
by Che-Chun Kuo · textwebappswindows
https://www.exploit-db.com/exploits/45400

Scores

CVSS v3 7.2
EPSS 0.0639
EPSS Percentile 91.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (19)
apache/syncope 1.0.0
apache/syncope 1.0.4
apache/syncope 1.0.5
apache/syncope 1.0.6
apache/syncope 1.0.7
apache/syncope 1.0.8
apache/syncope 1.0.9
apache/syncope 1.1.0
apache/syncope 1.1.1
apache/syncope 1.1.2
... and 9 more
Published Mar 20, 2018
Tracked Since Feb 18, 2026