Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Avaya WebLM Improper Restriction of XML External Entity Reference
Vulnerability Description
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Vulnerability Title
Avaya WebLM 代码问题漏洞
Vulnerability Description
Avaya WebLM是美国Avaya公司的一个用于管理组织中Avaya设备的管理器。 Avaya WebLM管理界面 7.0版本到7.1.3.6版本和8.0版本到8.1.2版本存在代码问题漏洞,该漏洞源于一个XML外部实体(XXE)漏洞允许经过身份验证的用户通过XML请求中的精心制作的DTD读取任意文件或进行服务器端请求伪造(SSRF)攻击。
CVSS Information
N/A
Vulnerability Type
N/A