CVE-2024-50848

MEDIUM

RWS Worldserver - XXE

Title source: rule
STIX 2.1

Description

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

Exploits (1)

nomisec WRITEUP
by 1mhr4b · poc
https://github.com/1mhr4b/CVE-2024-50848

Scores

CVSS v3 6.5
EPSS 0.0785
EPSS Percentile 92.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
rws/worldserver 11.8.2
Published Nov 18, 2024
Tracked Since Feb 18, 2026