CVE-2019-10264: XEE
Published Jul 26, 2019
·Updated
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This option accepts a ZIP archive containing a users.xml file that can trigger XXE.
Affected Software
1 affected component
Ahsay Cloud Backup Suite<8.1.1.50
Event History
Jul 26, 2019
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10264?
The severity of CVE-2019-10264 is rated high with a CVSS score of 7.2.
2
What vulnerability type is CVE-2019-10264?
CVE-2019-10264 is classified as an XML External Entity (XXE) vulnerability.
3
How do I fix CVE-2019-10264?
To fix CVE-2019-10264, upgrade to Ahsay Cloud Backup Suite version 8.1.1.50 or later.
4
What is affected by CVE-2019-10264?
CVE-2019-10264 affects versions of Ahsay Cloud Backup Suite prior to 8.1.1.50.
5
Can CVE-2019-10264 be exploited remotely?
Yes, CVE-2019-10264 can be exploited remotely by an authenticated administrator through the 'Move / Import / Export Users' screen.