CVE-2018-19371

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
02/01/2019
Last modified:
24/01/2019

Description

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sdl:web_content_manager:8.5.0:*:*:*:*:*:*:*