Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It was possible to inject malicious XML data through several access points.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-15T12:35:09

Updated: 2021-09-15T12:35:09

Reserved: 2021-04-05T00:00:00


Link: CVE-2021-30137

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-15T13:15:07.903

Modified: 2021-09-28T00:54:25.003


Link: CVE-2021-30137

JSON object: View

cve-icon Redhat Information

No data.

CWE