OpenMRS 2.3 (1.11.4) XXE Injection...

- AV AC AU C I A
发布: 2015-12-08
修订: 2025-04-13

OpenMRS version 2.3 (1.11.4) suffers from an XML external entity processing vulnerability. The vulnerability is caused due to an error when parsing XML entities within ZIP archives and can be exploited to e.g. disclose data from local resources or cause a DoS condition (billion laughs) via a specially crafted XML file including external entity references.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息