Vulnerabilities > CVE-2018-1000090 - XXE vulnerability in Textpattern 4.6.2

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
textpattern
CWE-611

Summary

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.

Vulnerable Configurations

Part Description Count
Application
Textpattern
1