← All CVEs

CVE-2018-1321

high · 7.2

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.

7.2
CVSS
17.5%
EPSS (exploit prob.)
97th
EPSS percentile
2018-03-20
Published

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachesyncope>= 1.2.0, < 1.2.11
apachesyncope>= 2.0.0, < 2.0.8
apachesyncope1.0.0
apachesyncope1.0.4
apachesyncope1.0.5
apachesyncope1.0.6
apachesyncope1.0.7
apachesyncope1.0.8
apachesyncope1.0.9
apachesyncope1.1.0
apachesyncope1.1.1
apachesyncope1.1.2
apachesyncope1.1.3
apachesyncope1.1.4
apachesyncope1.1.5
apachesyncope1.1.6
apachesyncope1.1.7
apachesyncope1.1.8
apachesyncope1.2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1321