CVE-2018-14485

CRITICAL

BlogEngine.NET 3.3 - XML External Entity (XXE)

Title source: llm

Description

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

Exploits (1)

exploitdb WRITEUP
by Netsparker · textwebappswindows
https://www.exploit-db.com/exploits/46106

Scores

CVSS v3 9.8
EPSS 0.4344
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (1)
blogengine/blogengine.net 3.3
Published May 07, 2019
Tracked Since Feb 18, 2026