Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/sbrl/Pepperminty-Wiki/issues/152 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-01-03T14:00:00Z
Updated: 2024-09-16T17:23:52.896Z
Reserved: 2018-01-03T00:00:00Z
Link: CVE-2017-1000497
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2018-01-03T14:29:00.317
Modified: 2020-10-19T17:43:12.197
Link: CVE-2017-1000497
Redhat
No data.