vendor:
MSN Password Recovery
by:
ZwX
8.8
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: MSN Password Recovery
Affected Version From: 1.30
Affected Version To: 1.30
Patch Exists: YES
Related CWE: N/A
CPE: a:top-password:msn_password_recovery
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
MSN Password Recovery 1.30 – XML External Entity Injection
An XML External Entity Injection (XXE) vulnerability exists in MSN Password Recovery 1.30. An attacker can exploit this vulnerability by creating a malicious XML file and hosting it on a web server. The attacker can then use the software to open the malicious XML file, which will cause the malicious payload to be executed. This can lead to the disclosure of sensitive information.
Mitigation:
To mitigate this vulnerability, users should ensure that they are running the latest version of MSN Password Recovery and that they are not opening any untrusted XML files.