Vulnerabilities > CVE-2018-1000515 - XXE vulnerability in News-Articles Project News-Articles 00.09.11

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
news-articles-project
CWE-611

Summary

ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server..

Vulnerable Configurations

Part Description Count
Application
News-Articles_Project
1