CVE-2019-13358

HIGH

Opencats < 0.9.4-3 - XXE

Title source: rule

Description

lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.

Exploits (1)

exploitdb WORKING POC
by Jake Ruston · pythonwebappsphp
https://www.exploit-db.com/exploits/50316

Scores

CVSS v3 7.5
EPSS 0.4127
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
opencats/opencats < 0.9.4-3
Published Jul 05, 2019
Tracked Since Feb 18, 2026