356
VMScore

CVE-2018-19371

Published: 02/01/2019 Updated: 24/01/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sdl web content manager 8.5.0

Exploits

SDL Web Content Manager version 850 suffers from an XML external entity injection vulnerability ...