CVE-2024-29010
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
01/05/2024
Last modified:
01/05/2024
Description
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information.<br />
<br />
This issue affects GMS: 9.3.4 and earlier versions.<br />
<br />
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH



