Record summary

CVE-2019-9757 has a selected CVSS score of 7.5 (high); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2019-9757Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files

Python · 76.1 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHLabKey Server 19.1.0 - XML External Entity (XXE)CVSS 7.5

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

Impact

Attackers can read arbitrary local files on the server, potentially leading to information disclosure.

Remediation

Update to the latest version of LabKey Server or apply security patches that fix XML parsing vulnerabilities.

WeaknessesCWE-611
Authorsritikchaddha
Template tagscvecve2019labkeyxxeauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:labkey:labkey_server:19.1.0:*:*:*:*:*:*:*
Shodan: title:"LabKey"
FOFA: title="LabKey"

Source: ProjectDiscovery

References

3