CVE-2024-51136

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openimaj:openimaj:1.3.10:*:*:*:*:*:*:*

History

06 Nov 2024, 19:31

Type Values Removed Values Added
CPE cpe:2.3:a:openimaj:openimaj:1.3.10:*:*:*:*:*:*:*
First Time Openimaj
Openimaj openimaj
CWE CWE-611
References () https://github.com/openimaj/openimaj - () https://github.com/openimaj/openimaj - Product
References () https://github.com/openimaj/openimaj/issues/382 - () https://github.com/openimaj/openimaj/issues/382 - Exploit
References () https://mvnrepository.com/artifact/org.openimaj.tools/WebTools - () https://mvnrepository.com/artifact/org.openimaj.tools/WebTools - Product

05 Nov 2024, 21:35

Type Values Removed Values Added
CWE CWE-91
Summary
  • (es) Una vulnerabilidad de entidad externa XML (XXE) en Dmoz2CSV en openimaj v1.3.10 permite a los atacantes acceder a información confidencial o ejecutar código arbitrario mediante el suministro de un archivo XML manipulado.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

04 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-04 17:15

Updated : 2024-11-06 19:31


NVD link : CVE-2024-51136

Mitre link : CVE-2024-51136

CVE.ORG link : CVE-2024-51136


JSON object : View

Products Affected

openimaj

  • openimaj
CWE
CWE-611

Improper Restriction of XML External Entity Reference

CWE-91

XML Injection (aka Blind XPath Injection)