Vulnerabilities > CVE-2019-10266 - XXE vulnerability in Ahsay Cloud Backup Suite

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ahsay
CWE-611
exploit available

Summary

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.

Exploit-Db

idEDB-ID:47181
last seen2019-07-26
modified2019-07-26
published2019-07-26
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/47181
titleAhsay Backup 7.x - 8.1.1.50 - XML External Entity Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153772/ahsaybackup7-xml.txt
idPACKETSTORM:153772
last seen2019-07-27
published2019-07-26
reporterWietse Boonstra
sourcehttps://packetstormsecurity.com/files/153772/Ahsay-Backup-7.x-8.x-XML-Injection.html
titleAhsay Backup 7.x / 8.x XML Injection