vendor:
SecureTrack
by:
konstantinos Alexiou
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: SecureTrack
Affected Version From: TufinOS 2.17 Build 1193
Affected Version To: TufinOS 2.17 Build 1193
Patch Exists: NO
Related CWE:
CPE: a:tufin:tufinos:2.17:build_1193
Platforms Tested:
2018
TufinOS 2.17 Build 1193 – XML External Entity Injection
The SecureTrack application is vulnerable to XML External Entity injection. This attack is considered quite serious and can be used to retrieve confidential data, perform denial of service, execute server side request forgery attacks, and perform port scanning through the machine on other systems. The vulnerability exists in the 'Audit' > 'Best Practices' module of the 'SecureTrack' application when creating a new Best Practices query and manipulating the 'xml' parameter in the request. When triggered, the vulnerability writes the contents of the requested file inside the name field of a best practice. This vulnerability affects every 'SecureTrack' application authentication user role.
Mitigation:
Reconfigure the XML processor to use a local static DTD