An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-12-19T15:00:07.403Z
Updated: 2024-08-02T08:28:21.761Z
Reserved: 2023-11-24T11:48:26.685Z
Link: CVE-2023-6280
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-19T15:15:09.033
Modified: 2024-11-21T08:43:31.727
Link: CVE-2023-6280
Redhat
No data.