CVE-2023-6280
19.12.2023, 15:15
An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.Enginsight
Vendor | Product | Version |
---|---|---|
52north | wps | 𝑥 < 4.0.0 |
52north | wps | 4.0.0:beta1 |
52north | wps | 4.0.0:beta10 |
52north | wps | 4.0.0:beta2 |
52north | wps | 4.0.0:beta3 |
52north | wps | 4.0.0:beta4 |
52north | wps | 4.0.0:beta5 |
52north | wps | 4.0.0:beta6 |
52north | wps | 4.0.0:beta7 |
52north | wps | 4.0.0:beta8 |
52north | wps | 4.0.0:beta9 |
𝑥
= Vulnerable software versions