An External XML entity (XXE)... CVE-2022-3338

- AV AC AU C I A
发布: 2022-10-18
修订: 2024-11-21

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.

0%
暂无可用Exp或PoC
当前有15条受影响产品信息