CVE-2023-42344: OpenCMS – XML external entity (XXE)

CVE-2023-42344: OpenCMS - XML external entity (XXE)-渗透云记 - 专注于网络安全与技术分享
CVE-2023-42344: OpenCMS – XML external entity (XXE)
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-42344: OpeNCMS – XML external entity (xxe)

漏洞描述

users can execute code without authentication. An attacker can execute malicious requests on the OpenCms server. When the requests are successful vulnerable OpenCms can be exploited resulting in an unauthenticated XXE vulnerability. Based on research OpenCMS versions from 9.0.0 to 10.5.0 are vulnerable.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享