Search

Contact Us

Log in

Vulnerabilities / XML external entity injection

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity
high
CWE NameXML external entity injection
CWE IDCWE-611
CWE Score7.5
Compliance
OWASP TOP10 -> A5
ISO 27001 -> A.8.9
HIPAA -> 164.306(a)
CVSS3.0
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
Confidentiality ImpactHigh
Integrity ImpactNone
Availability ImpactNone
XML external entity injection