CVE-2020-11586

CRITICAL

CIPPlanner CIPAce < 9.1 - Unauthenticated XML External Entity Injection

Title source: llm
STIX 2.1

Description

An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0125
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (1)
cipplanner/cipace < 9.1
Published Apr 06, 2020
Tracked Since Feb 18, 2026