CVE-2021-46365: XEE
Published Feb 11, 2022
·Updated
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.
Affected Software
1 affected component
Magnolia-cms Magnolia Cms<6.2.4
Event History
Feb 11, 2022
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-46365?
CVE-2021-46365 is considered a high severity vulnerability due to its potential to allow XML External Entity attacks.
2
How do I fix CVE-2021-46365?
To fix CVE-2021-46365, upgrade to Magnolia CMS version 6.2.4 or later.
3
What versions of Magnolia CMS are affected by CVE-2021-46365?
Magnolia CMS versions 6.2.3 and below are affected by CVE-2021-46365.
4
What type of attack does CVE-2021-46365 enable?
CVE-2021-46365 enables attackers to execute XML External Entity (XXE) attacks.
5
What is the impact of exploiting CVE-2021-46365?
Exploiting CVE-2021-46365 can lead to data disclosure and potentially control over the server environment.