CVE-2018-20000
10.12.2018, 02:29
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.Enginsight
Vendor | Product | Version |
---|---|---|
apereo | bw-webdav | 𝑥 < 4.0.3 |
𝑥
= Vulnerable software versions