CVE-2017-18197

CRITICAL9.8EPSS 0.44%

mxGraph vulnerable to XXE attacks

Published: 5/14/2022Modified: 11/8/2023
Also known as:GHSA-wvpv-8524-wg6xDEBIAN-CVE-2017-18197

Description

In `mxGraphViewImageReader.java` in mxGraph before 3.7.6, the `SAXParserFactory` instance in `convert()` is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by `/ServerView`.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (6)