CVE-2018-8940
CRITICALEnghouse Cloud Contact Center Platform 7.2.5 - XML External Entity Injection via ClientServiceConfigController
Title source: llmDescription
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.
References (1)
Core 1
Core References
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/fulldisclosure/2019/May/9
Scores
CVSS v3
9.8
EPSS
0.0163
EPSS Percentile
73.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (1)
enghouse/contact_center\
_service_provider 7.2.5
Published
May 14, 2019
Tracked Since
Feb 18, 2026