Impact
CentreStack versions before 17.4 are vulnerable to an XML external entity (XXE) injection flaw. By supplying a malicious URL to the SharePoint storage configuration handler, an attacker can cause the server to retrieve and parse attacker‑controlled XML that contains external DTD references. This causes out‑of‑band retrieval of arbitrary files from the server, such as configuration files that may hold database credentials or cryptographic keys. The result is a loss of confidentiality and potential compromise of sensitive data.
Affected Systems
The affected product is CentreStack from Gladinet. Versions earlier than 17.4 contain the flaw; the exact sub‑release list is not specified in the advisory.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score is below 1 %, indicating that the likelihood of exploitation at this time is low, and it is not listed in the CISA KEV catalog. The flaw is remotely exploitable via an unauthenticated request to the StorageConfig endpoint, so an attacker only needs network access to the target to send a crafted request. Once the request is processed, the server will fetch the attacker‑provided XML, leading to unauthorized file exfiltration.
OpenCVE Enrichment