CVE-2018-14473
04.08.2018, 01:29
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ocsinventory-ng | ocsinventory_ng | 2.4.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases