vendor:
Hippo CMS
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
XML External Entity Information Disclosure
611
CWE
Product Name: Hippo CMS
Affected Version From: 10.1
Affected Version To: 7.8
Patch Exists: YES
Related CWE: N/A
CPE: a:hippo:hippo_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.32-5-xen-amd64, Java/1.8.0_66, Apache-Coyote/1.1
2016
Hippo CMS 10.1 XML External Entity Information Disclosure Vulnerability
XXE (XML External Entity) processing through upload of SVG images in the CMS, and through XML import in the CMS Console application.
Mitigation:
Disable XML external entity processing in the application.