XXE attack in Energy Management Suite - CVE-2018-15444
Published: November 8, 2018
Vulnerability identifier: #VU15762
CSH Severity: Low
CVSS v4: 5.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15444
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to conduct XXE-attack.
The vulnerability exists in the web-based user interface due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can trick the victim into open an XML file that submits malicious input and read and write files within the affected application.
Affected software
Energy Management Suite
How to mitigate CVE-2018-15444
Install updates from vendor's website.