CVE-2018-14473: XEE
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14473?
CVE-2018-14473 is rated as a medium severity vulnerability due to its potential for information exfiltration and Denial of Service.
How do I fix CVE-2018-14473?
To fix CVE-2018-14473, upgrade OCS Inventory to the latest version that addresses the XML parsing configuration issue.
What types of attacks can exploit CVE-2018-14473?
CVE-2018-14473 can be exploited by sending crafted HTTP requests that utilize XML external entities.
What are the consequences of exploiting CVE-2018-14473?
Exploiting CVE-2018-14473 may lead to sensitive information disclosure or a Denial of Service condition.
Is my system vulnerable if I am using OCS Inventory version 2.4.1?
Yes, systems running OCS Inventory version 2.4.1 are vulnerable to CVE-2018-14473 and should be updated immediately.