CVE-2018-8940
CCSP 7.2.5 API XML Injection / Server-Side Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.
El archivo ClientServiceConfigController.cs en Enghouse Cloud Contact Center Platform versión 7.2.5, tiene una funcionalidad para cargar archivos XML externos y analizarlos, lo que permite a un atacante cargar un archivo XML malicioso y hacer referencia a él en la URL de la aplicación, forzando a la aplicación a cargar y analizar el Archivo XML malicioso, tambié se conoce como un problema XXE.
Enghouse Interactive's CCSP version 7.2.5 suffers from API related XML external entity injection server-side request forgery vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-22 CVE Reserved
- 2019-05-11 CVE Published
- 2019-05-11 First Exploit
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/152829 | 2019-05-11 | |
https://seclists.org/fulldisclosure/2019/May/9 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enghouse Search vendor "Enghouse" | Contact Center: Service Provider Search vendor "Enghouse" for product "Contact Center: Service Provider" | 7.2.5 Search vendor "Enghouse" for product "Contact Center: Service Provider" and version "7.2.5" | - |
Affected
|