CVE-2018-17289: XEE
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17289?
CVE-2018-17289 has been classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2018-17289?
To fix CVE-2018-17289, update Kofax Front Office Server to the latest version that addresses the XML external entity vulnerability.
Who is affected by CVE-2018-17289?
CVE-2018-17289 affects remote authenticated users of Kofax Front Office Server Administration Console version 4.1.1.11.0.5212.
What type of vulnerability is CVE-2018-17289?
CVE-2018-17289 is an XML external entity (XXE) vulnerability.
Can CVE-2018-17289 be exploited remotely?
Yes, CVE-2018-17289 can be exploited remotely by authenticated users through crafted XML files.