TablePress <= 1.8 - XML External Entity Injection

2017-07-04 00:00
Yuji Tounai

Strategic Overview

Status
Patched in 1.8.1
Affected Version<= 1.8
CVSS4.3Medium
CVECVE-2017-10889
View all TablePress – Tables in WordPress made easy vulnerabilities

Vulnerability Overview

TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

Technical Analysis

REMEDIATION: Update to version 1.8.1, or a newer patched version --- IDENTIFIER: CWE-611 (Improper Restriction of XML External Entity Reference) The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C