Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2018-3713 Vulnerability in npm package angular-http-server
CVE-2023-5571 Vulnerability in npm package @vrite/sdk
CVE-2022-24279 Vulnerability in npm package madlib-object-utils
CVE-2021-21351 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser