52North WPS XML External Entity (XXE) Vulnerability

52North WPS XML External Entity (XXE) Vulnerability

CVE-2023-6280 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

Learn more about our Web App Pen Testing.