ZeroHour

CVE-2018-12243

CVSS 3.0
8.8 high
EPSS
<1%p53
Published
()
Modified
Description

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

Vendors
symantec
Products
messaging gateway
Weakness
CWE-611
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.