CVE-2020-37192
MEDIUMMSN Password Recovery 1.30 - Info Disclosure
Title source: llmDescription
MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.
Exploits (1)
Scores
CVSS v3
6.2
EPSS
0.0002
EPSS Percentile
6.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-611
Status
draft
Timeline
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026