Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2019-16776 Vulnerability in npm package npm
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r4b
CVE-2023-33831 Vulnerability in npm package @frangoteam/fuxa
CVE-2021-21254 Vulnerability in npm package @ckeditor/ckeditor5-markdown-gfm
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api