CVE-2018-1000823
20.12.2018, 15:29
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.Enginsight
Vendor | Product | Version |
---|---|---|
exist-db | exist | 𝑥 < 5.0.0 |
exist-db | exist | 5.0.0:rc1 |
exist-db | exist | 5.0.0:rc2 |
exist-db | exist | 5.0.0:rc3 |
exist-db | exist | 5.0.0:rc4 |
𝑥
= Vulnerable software versions