Impact
An XML external entity (XXE) flaw in the /designer/loadReport endpoint of SpringBlade v4.8.0 lets authenticated users supply crafted XML that can resolve external entities on the host, enabling arbitrary code execution. The weakness arises from the XML parser permitting external entity resolution, a classic CWE‑611 issue. An attacker can run commands or otherwise compromise the server, affecting confidentiality, integrity, and availability of the application and underlying system.
Affected Systems
SpringBlade version 4.8.0 is affected. No vendor or product details beyond this version are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% signals a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have access to the /designer/loadReport endpoint to inject a malicious XML payload and gain code execution. Although exploitation remains unlikely, the severity remains high enough to warrant prompt remediation.
OpenCVE Enrichment