CVE-2018-3881

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
01/08/2018
Last modified:
03/02/2023

Description

An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:focalscope:focalscope:2416:*:*:*:*:*:*:*