← All CVEs

CVE-2013-3617

low · 3.5

The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

3.5
CVSS
21.1%
EPSS (exploit prob.)
97th
EPSS percentile
2013-11-02
Published

AV:N/AC:M/Au:S/C:P/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
openbravoopenbravo_erp<= 3.0
openbravoopenbravo_erp2.40
openbravoopenbravo_erp2.50

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-3617