CVE-2018-1321: Input Validation
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11 and 2.0.x before 2.0.8 can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
Other sources
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1321?
CVE-2018-1321 is a vulnerability in Apache Syncope that allows an administrator with report and template entitlements to perform malicious operations, including file read and write, using XSL Transformations (XSLT).
How can an administrator exploit CVE-2018-1321?
An administrator can exploit CVE-2018-1321 by using XSL Transformations (XSLT) to perform malicious operations, such as file read and write.
Which versions of Apache Syncope are affected by CVE-2018-1321?
Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x are affected by CVE-2018-1321.
What is the severity of CVE-2018-1321?
CVE-2018-1321 has a severity rating of 7.2, indicating a high severity.
Are there any references available for CVE-2018-1321?
Yes, you can find references for CVE-2018-1321 at the following URLs: [http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlements](http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlements), [http://www.securityfocus.com/bid/103508](http://www.securityfocus.com/bid/103508), [https://www.exploit-db.com/exploits/45400/](https://www.exploit-db.com/exploits/45400/)