LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.
References
Link | Resource |
---|---|
https://0dd.zone/2018/08/05/LatexDraw-XXE/ | Exploit Third Party Advisory |
https://github.com/arnobl/latexdraw/issues/10 | Exploit Issue Tracking Patch Third Party Advisory |
https://0dd.zone/2018/08/05/LatexDraw-XXE/ | Exploit Third Party Advisory |
https://github.com/arnobl/latexdraw/issues/10 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://0dd.zone/2018/08/05/LatexDraw-XXE/ - Exploit, Third Party Advisory | |
References | () https://github.com/arnobl/latexdraw/issues/10 - Exploit, Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2018-08-20 19:31
Updated : 2024-11-21 03:40
NVD link : CVE-2018-1000639
Mitre link : CVE-2018-1000639
CVE.ORG link : CVE-2018-1000639
JSON object : View
Products Affected
latexdraw_project
- latexdraw
CWE
CWE-611
Improper Restriction of XML External Entity Reference