packetstormsecurity.com
http://packetstormsecurity.com/files/164253/OpenCats-0.9.4-2-XML-Injection.html CVE-2019-13358
HIGH
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
Record summary
CVE-2019-13358 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)ExploitDB exploitby Jake RustonNot analyzed1 file
References
5opencats.org
http://www.opencats.org/news doddsecurity.com
https://doddsecurity.com/312/xml-external-entity-injection-xxe-in-opencats-applicant-tracking-system github.com
https://github.com/opencats/OpenCATS/pull/440 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-13358