vendor:
Ladon Framework for Python
by:
Redteam Pentesting
7,5
CVSS
HIGH
XML External Entity Expansion
611
CWE
Product Name: Ladon Framework for Python
Affected Version From: 0.9.40 and previous
Affected Version To: none
Patch Exists: NO
Related CWE: GENERIC-MAP-NOMATCH
CPE: a:ladon_framework:ladon_framework_for_python
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Mac and Linux
2016
Advisory: XML External Entity Expansion in Ladon Webservice
Attackers who can send SOAP messages to a Ladon webservice via the HTTP interface of the Ladon webservice can exploit an XML external entity expansion vulnerability and read local files, forge server side requests or overload the service with exponentially growing memory payloads.
Mitigation:
The vendor has been notified and is currently working on a patch.