I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-1848 I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Scilico
Scilico i\, Librarian
CPEs cpe:2.3:a:i-librarian:i\,_librarian:*:*:*:*:*:*:*:* cpe:2.3:a:scilico:i\,_librarian:*:*:*:*:*:*:*:*
Vendors & Products I-librarian
I-librarian i\, Librarian
Scilico
Scilico i\, Librarian
Metrics cvssV3_0

{'score': 10.0, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 10.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T02:01:01.634Z

Reserved: 2018-03-13T00:00:00Z

Link: CVE-2018-1000124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-03-13T21:29:00.320

Modified: 2025-12-05T20:14:36.020

Link: CVE-2018-1000124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses