5.5
CVSSv3

CVE-2018-1000069

Published: 13/03/2018 Updated: 14/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

FreePlane version 1.5.9 and previous versions contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

Vulnerable Product Search on Vulmon Subscribe to Product

freeplane freeplane

debian debian linux 7.0

debian debian linux 9.0

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #893663 freeplane: CVE-2018-1000069 XXE vulnerability Package: freeplane; Maintainer for freeplane is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for freeplane is src:freeplane (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Tue, 20 ...
Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened For the oldstable distribution (jessie), this problem has been fixed in version 1312-1+deb8u1 For th ...