Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2022-48285 Vulnerability in maven package org.webjars.npm:jszip
CVE-2018-10054 Vulnerability in maven package com.h2database:h2
CVE-2021-21169 Vulnerability in npm package electron
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-jasper
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils