CVE-2018-1000069: XEE
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000069?
CVE-2018-1000069 is classified as a critical vulnerability due to its potential to allow an attacker to steal sensitive data from the victim's machine.
How do I fix CVE-2018-1000069?
To fix CVE-2018-1000069, upgrade FreePlane to version 1.7.5-1 or later.
Which versions of FreePlane are affected by CVE-2018-1000069?
FreePlane versions 1.5.9 and earlier are affected by CVE-2018-1000069.
Can CVE-2018-1000069 be exploited without user interaction?
Exploitation of CVE-2018-1000069 requires the victim to open a specially crafted mind map file.
What type of vulnerability is CVE-2018-1000069?
CVE-2018-1000069 is an XML External Entity (XXE) vulnerability in the XML parser.