CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2014-3244

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1040%
EPSS Percentile40.14th
Published2018年2月1日
Last Modified2024年11月21日

Vulnerability Description

XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

Affected Platforms (CPE)

📦
Sugarcrm

Sugarcrm

< 6.5.16

References & Advisories

相關漏洞威脅