vendor:
Dive Assistant Desktop
by:
Trent Gordon
5,5
CVSS
MEDIUM
XXE Injection
611
CWE
Product Name: Dive Assistant Desktop
Affected Version From: 8.0
Affected Version To: 8.0
Patch Exists: Yes
Related CWE: CVE-2017-8918
CPE: a:blackwave:dive_assistant_desktop:8.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1, Windows 10
2017
Dive Assistant – Template Builder XXE Injection
Dive Assistant - Desktop Edition comes with a template builder .exe to create print templates. The templates are saved and uploaded as XML files which are vulnerable to XXE injection. Sending a crafted payload to a user, when opened in Dive Assistant - Template Builder, will return the content of any local files to a remote attacker.
Mitigation:
Ensure that XML documents are not processed in an unsafe manner, and that external entities are not allowed to be referenced.