CVE-2022-38840
HIGH EXPLOITED NUCLEIGralp MAN-EAM-0003 3.2.4 - XML External Entity Injection via XML File Upload
Title source: llmExploitation Summary
CVE-2022-38840 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Ahmed Alroky. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) vulnerability in Guralp Systems' MAN-EAM-0003 V3.2.4, allowing an attacker to read arbitrary files (e.g., /etc/passwd) by uploading a malicious XML file to the xmlstatus.cgi endpoint.
Description
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.
Exploits (1)
This exploit demonstrates an XXE (XML External Entity) vulnerability in Guralp Systems' MAN-EAM-0003 V3.2.4, allowing an attacker to read arbitrary files (e.g., /etc/passwd) by uploading a malicious XML file to the xmlstatus.cgi endpoint.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N