CVE-2017-18197

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
24/02/2018
Last modified:
12/03/2018

Description

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jgraph:mxgraph:*:*:*:*:*:*:*:* 3.7.5 (including)