N-central - XML External Entities Injection
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
N-centralPoC 已收录
CVSS8.4
暂无产品描述。
共找到 3 条公开漏洞记录
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.