VulnerabilityModified
CVE-2018-19371
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
MEDIUM 6.5EPSS 6.02%
Does this matter?
Lower severity and a low EPSS score (6.02%). Track it; it rarely justifies an emergency change on its own.
Description
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 6.02% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- sdl/web content manager
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/150826/SDL-Web-Content-Manager-8.5.0-XML-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46000/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/150826/SDL-Web-Content-Manager-8.5.0-XML-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46000/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.