Vulnerabilities > Osgeo > Pywps > 4.2.6

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-39371 XXE vulnerability in multiple products
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity.
network
low complexity
osgeo debian CWE-611
5.0