ZeroHour

CVE-2018-1000639

PoC ×2
CVSS 3.1
9.6 critical
EPSS
2%p74
Published
()
Modified
Description

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

Vendors
latexdraw project
Products
latexdraw
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.