FreeIPA - XML Entity Injection
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.
FreeIPAPoC 已收录
CVSS7.5EPSS 91.6%