Vulnerabilities > CVE-2017-17762 - XXE vulnerability in Episerver 7
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |