CVE-2020-14478 - CERT CVE
ID CVE-2020-14478
Sažetak A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
Reference
CVSS
Base: 5.6
Impact: 7.8
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE NONE PARTIAL
CVSS vektor AV:L/AC:L/Au:N/C:C/I:N/A:P
Zadnje važnije ažuriranje 04-03-2022 - 16:58
Objavljeno 24-02-2022 - 19:15