9.8
CVSSv3

CVE-2018-14485

Published: 07/05/2019 Updated: 08/05/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blogengine blogengine.net 3.3

Exploits

XML External Entity Injection Vulnerability in BlogEngine 33 Information -------------------- Advisory by Netsparker Name: XML External Entity Injection Vulnerability in BlogEngine 33 Affected Software: BlogEngine Affected Versions: 33 Homepage: blogengineio/ Vulnerability: XML External Entity (XXE) Injection Vulnerability Severity: H ...