First published: Wed Jan 02 2019(Updated: )
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SDL Web Content Manager | =8.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19371 has been classified as a high severity vulnerability due to its potential to compromise sensitive files on the system.
To fix CVE-2018-19371, ensure that you upgrade to a patched version of SDL Web Content Manager beyond 8.5.0.
CVE-2018-19371 is an XML External Entity (XXE) vulnerability affecting SDL Web 8.5.0.
CVE-2018-19371 can allow attackers to read sensitive files from the server's filesystem.
Yes, CVE-2018-19371 specifically affects SDL Web Content Manager version 8.5.0.