Vulnerabilities > CVE-2022-31447 - XXE vulnerability in Magicpin 3.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
magicpin
CWE-611

Summary

An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.

Vulnerable Configurations

Part Description Count
Application
Magicpin
1