XXE Zeroday Vulnerability in HP PPM

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Intro: XXE Zeroday Vulnerability in HP PPM Researchers at Rhino Security Labs discovered an XXE vulnerability in the way HP Project and Portfolio Management Center (HP PPM) processed imported tickets. Specifically, an XML external entity injection vulnerability allows an attacker to exploit the application that parses XML input and reflects it back to the user without any validation. Misconfiguration of the XML parser permits the execution of malicious input. This vulnerability allows for a local file read of the system, yielding file read access to any authenticated user, and can be remotely exploited to execute a Man-in-the Middle (MitM) attack and Cross-site Request Forgery (CSRF). An attacker can compromise an application through an XML external entity exploit and carry out serious attacks such as obtaining sensitive information, denial of service, port scanning, server-side request forgery, and others. ### What is XML External Entity (XXE) Injection? XML External Entity...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息