CVE-2025-58360: GeoServer – XML External Entity Injection

CVE-2025-58360: GeoServer - XML External Entity Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2025-58360: GeoServer – XML External Entity Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-58360: geoserver – XML External Entity Injection

漏洞描述

GeoServer 2.26.0 to 2.26.2 and 2.25.6 contains an XML External Entity (xxe) injection caused by insufficient sanitization of XML input in /geoserver/wms GetMap operation, letting attackers disclose files or cause DoS, exploit requires crafted XML input.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享