Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2019-14772 Vulnerability in npm package verdaccio
CVE-2020-26291 Vulnerability in maven package org.webjars.bower:urijs
CVE-2020-2322 Vulnerability in maven package io.jenkins.plugins:chaos-monkey
CVE-2018-20834 Vulnerability in maven package org.webjars:tar
CVE-2022-33987 Vulnerability in maven package org.webjars.npm:got