Vulnerabilities > CVE-2017-1000497 - XXE vulnerability in Pepperminty-Wiki Project Pepperminty-Wiki 0.15

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
pepperminty-wiki-project
CWE-611
critical

Summary

Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution

Vulnerable Configurations

Part Description Count
Application
Pepperminty-Wiki_Project
1