Vulnerabilities > CVE-2020-26705 - XXE vulnerability in Easyxml Project Easyxml 0.5.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
HIGH Summary
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |