Vulnerabilities > CVE-2018-19371 - XXE vulnerability in SDL web Content Manager 8.5.0

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sdl
CWE-611
exploit available

Summary

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

Vulnerable Configurations

Part Description Count
Application
Sdl
1

Exploit-Db

fileexploits/xml/webapps/46000.txt
idEDB-ID:46000
last seen2018-12-19
modified2018-12-18
platformxml
port
published2018-12-18
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46000
titleSDL Web Content Manager 8.5.0 - XML External Entity Injection
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/150826/sdlwcm850-xxe.txt
idPACKETSTORM:150826
last seen2018-12-25
published2018-12-18
reporterAhmed Elhady Mohamed
sourcehttps://packetstormsecurity.com/files/150826/SDL-Web-Content-Manager-8.5.0-XML-Injection.html
titleSDL Web Content Manager 8.5.0 XML Injection