I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-13T21:00:00Z

Updated: 2024-09-17T02:01:01.634Z

Reserved: 2018-03-13T00:00:00Z

Link: CVE-2018-1000124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-03-13T21:29:00.320

Modified: 2018-04-13T14:26:16.663

Link: CVE-2018-1000124

cve-icon Redhat

No data.