CVE-2019-13358
HIGHOpencats < 0.9.4-3 - XXE
Title source: ruleDescription
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.4127
EPSS Percentile
97.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-611
Status
published
Products (1)
opencats/opencats
< 0.9.4-3
Published
Jul 05, 2019
Tracked Since
Feb 18, 2026