CVE-2019-13358
HIGHOpenCats < 0.9.4-3 - XML External Entity Injection via DOCX/ODT File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-13358. PoCs published by Jake Ruston.
AI-analyzed exploit summary This exploit leverages an XXE vulnerability in OpenCATS to read arbitrary files from the server by embedding a malicious XML entity in a crafted DOCX file. The exploit automates the process of creating, uploading, and retrieving the file contents via base64 encoding.
Description
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
Exploits (1)
This exploit leverages an XXE vulnerability in OpenCATS to read arbitrary files from the server by embedding a malicious XML entity in a crafted DOCX file. The exploit automates the process of creating, uploading, and retrieving the file contents via base64 encoding.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N