CVE-2018-5758

MEDIUM

Aurea Jive-n 9.0.2.1 - XML External Entity Injection via Upload File Functionality

Title source: llm
STIX 2.1

Description

The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0313
EPSS Percentile 86.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
aurea/jive-n 9.0.2.1
Published Mar 12, 2018
Tracked Since Feb 18, 2026