CVE-2019-9757
LabKey Server 19.1.0 - XML External Entity (XXE)
Record summary
CVE-2019-9757 has a selected CVSS score of 7.5 (high); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Description
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.
Exploitation context
Proofs of concept
1Curated repository PoCs
GitHubCVE-2019-9757Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files
Nuclei templates
1ProjectDiscoveryHIGHLabKey Server 19.1.0 - XML External Entity (XXE)CVSS 7.5
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.
Impact
Attackers can read arbitrary local files on the server, potentially leading to information disclosure.
Remediation
Update to the latest version of LabKey Server or apply security patches that fix XML parsing vulnerabilities.
Source: ProjectDiscovery