CVE-2018-1000836
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
bw-calendar-engine, en versiones iguales o anteriores a la bw-calendar-engine-3.12.0, contiene una vulnerabilidad de XEE (XML External Entity) en el analizador de XML IscheduleClient que puede resultar en la divulgación de datos confidenciales, una denegación de servicio (DoS), Server-Side Request Forgery (SSRF) o el escaneo de puertos. El ataque parece ser explotable mediante un Man-in-the-Middle (MitM) o un servidor malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-20 CVE Reserved
- 2018-12-20 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://0dd.zone/2018/10/28/bw-calendar-engine-XXE-MitM | Third Party Advisory | |
https://github.com/Bedework/bw-calendar-engine/issues/3 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apereo Search vendor "Apereo" | Bw-calendar-engine Search vendor "Apereo" for product "Bw-calendar-engine" | <= 3.12.0 Search vendor "Apereo" for product "Bw-calendar-engine" and version " <= 3.12.0" | - |
Affected
|