#VU42759 Input validation error in Crowd Server - CVE-2013-3925
Published: July 2, 2013 / Updated: August 11, 2020
Crowd Server
Atlassian
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.