CVE-2023-6280
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
19/12/2023
Last modified:
02/08/2024
Description
An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:52north:wps:*:*:*:*:*:*:*:* | 4.0.0 (excluding) | |
| cpe:2.3:a:52north:wps:4.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta8:*:*:*:*:*:* | ||
| cpe:2.3:a:52north:wps:4.0.0:beta9:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



