CRITICAL🇵🇱 Wersja polska

CVE-2020-11586

CVSS 9.8v3.1pub. 2020-04-06upd. 2024-11-21

An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cipplanner Cipace

    APP
    Cipplanner
    < 9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassXXE
CWE
References

Related vulnerabilities

CVE-2020-11598CRITICAL9.8PL ✓same product

CIPAce 9.1 – nieuwierzytelniony upload i RCE przez plik ASHX

CVE-2020-11597CRITICAL9.8PL ✓same product

SQL Injection bez uwierzytelnienia w CIPPlanner CIPAce 9.1

CVE-2024-50619HIGH8.8same product

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attac...

CVE-2024-50617HIGH7.5same product

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow at...

CVE-2024-50620HIGH8.8same product

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document man...