668
VMScore

CVE-2018-8940

Published: 14/05/2019 Updated: 15/05/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an malicious user to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

enghouse contact center\\ _service_provider

Exploits

Enghouse Interactive's CCSP version 725 suffers from API related XML external entity injection server-side request forgery vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Enghouse Interactive´s CCSP 725 API XXE and SSRF,vulnerability via unauthenticated GET Request <!--X-Subject-Header ...