CVE-2024-29010

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
Summary
  • (es) El documento XML procesado en el endpoint URL de GMS ECM es vulnerable a la inyección de entidad externa XML (XXE), lo que podría resultar en la divulgación de información confidencial. Este problema afecta a GMS: 9.3.4 y versiones anteriores.
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0007 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0007 -

01 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 18:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-29010

Mitre link : CVE-2024-29010

CVE.ORG link : CVE-2024-29010


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference