Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2022-34305 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2022-36919 Vulnerability in maven package org.jenkins-ci.plugins:coverity
CVE-2015-6748 Vulnerability in maven package org.jsoup:jsoup
CVE-2020-11022 Vulnerability in maven package org.webjars:jquery
CVE-2016-10707 Vulnerability in maven package org.webjars:jquery