vendor:
BlogEngine
by:
Daniel Martinez Adan (aDoN90)
3
CVSS
LOW
XML External Entity (XXE OOB) Injection Vulnerability
611
CWE
Product Name: BlogEngine
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: -
CPE: -
Platforms Tested:
2020
BlogEngine 3.3 – ‘syndication.axd’ XML External Entity Injection
The vulnerability allows an attacker to inject malicious XML entities, leading to various types of attacks including server-side request forgery (SSRF) and exfiltration of sensitive data.
Mitigation:
Upgrade to a fixed version of BlogEngine (3.3 or later).