CVE-2018-1321

HIGH

Apache Syncope 1.2.0-1.2.10 - Authenticated Remote Code Execution via XSLT

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-1321. PoCs published by Che-Chun Kuo.

AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Apache Syncope 2.0.7: RCE via XSLT injection in Reports/Templates and information disclosure via FIQL/ORDER BY sorting. The XSLT payloads show file read and command execution, while the FIQL/ORDER BY technique recovers sensitive data like security answers.

Description

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

Exploits (1)

exploitdb WORKING POC
by Che-Chun Kuo · textwebappswindows
https://www.exploit-db.com/exploits/45400

This exploit demonstrates two vulnerabilities in Apache Syncope 2.0.7: RCE via XSLT injection in Reports/Templates and information disclosure via FIQL/ORDER BY sorting. The XSLT payloads show file read and command execution, while the FIQL/ORDER BY technique recovers sensitive data like security answers.

Classification
Working Poc 100%
Attack Type
Rce | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Apache Syncope 2.0.7
Auth required
Prerequisites: Access to Reports and Templates functionality · User entitlements to /syncope/rest/users endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103508
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45400/

Scores

CVSS v3 7.2
EPSS 0.0639
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (19)
apache/syncope 1.0.0
apache/syncope 1.0.4
apache/syncope 1.0.5
apache/syncope 1.0.6
apache/syncope 1.0.7
apache/syncope 1.0.8
apache/syncope 1.0.9
apache/syncope 1.1.0
apache/syncope 1.1.1
apache/syncope 1.1.2
... and 9 more
Published Mar 20, 2018
Tracked Since Feb 18, 2026