7.8
CVSSv3

CVE-2021-46365

Published: 11/02/2022 Updated: 19/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue in the Export function of Magnolia v6.2.3 and below allows malicious users to execute XML External Entity attacks via a crafted XLF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magnolia-cms magnolia cms

Github Repositories

CVE-2021-46365: Unsafe XML Parsing in Magnolia CMS

CVE-2021-46365: Unsafe XML Parsing in Magnolia CMS An issue in the Export function of Magnolia v623 and below allows attackers to execute XML External Entity attacks via a crafted XLF file Vendor Disclosure: The vendor's disclosure and fix for this vulnerability can be found here Requirements: This vulnerability requires: Valid user credentials Proof Of Concept: Mor