vendor:
XMLBlueprint XML Editor
by:
Javier Olmedo
8.1
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: XMLBlueprint XML Editor
Affected Version From: 16.191112
Affected Version To: 16.191112
Patch Exists: NO
Related CWE: CVE-2019-19032
CPE: a:xmlblueprint:xml_editor:16.191112
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro
2018
XMLBlueprint 16.191112 – XML External Entity Injection
XMLBlueprint XML Editor version 16.191112 and before are affected by XML External Entity Injection vulnerability through the malicious XML file. This allows a malicious user to read arbitrary files.
Mitigation:
Update to the latest version of XMLBlueprint XML Editor