7.2
CVSSv3

CVE-2018-1321

Published: 20/03/2018 Updated: 25/04/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An administrator with report and template entitlements in Apache Syncope 1.2.x prior to 1.2.11, 2.0.x prior to 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

apache syncope 1.0.8

apache syncope 1.1.0

apache syncope 1.1.7

apache syncope 1.2.0

apache syncope 1.0.0

apache syncope 1.0.4

apache syncope 1.0.5

apache syncope 1.0.6

apache syncope

apache syncope 1.1.1

apache syncope 1.1.2

apache syncope 1.1.3

apache syncope 1.1.4

apache syncope 1.1.5

apache syncope 1.0.7

apache syncope 1.0.9

apache syncope 1.1.6

apache syncope 1.1.8

Exploits

# Exploit Title: Apache Syncope 207 - Remote Code Execution # Date: 2018-09-12 # Exploit Author: Che-Chun Kuo # Vendor Homepage: syncopeapacheorg/ # Software Link: archiveapacheorg/dist/syncope/ # Version: 207 # Tested on: Windows # Advisory: syncopeapacheorg/security # CVE: CVE-2018-1321, CVE-2018-1322 # Vulnerabi ...
Apache Syncope version 27 suffers from a remote code execution vulnerability ...