Vulnerabilities > CVE-2017-1000497 - XXE vulnerability in Pepperminty-Wiki Project Pepperminty-Wiki 0.15

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pepperminty-wiki-project
CWE-611

Summary

Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution

Vulnerable Configurations

Part Description Count
Application
Pepperminty-Wiki_Project
1