Description
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin Find My Blocks Information Disclosure (3.3.2)
PHP Other Vulnerability (CVE-2015-4644)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6624)
WordPress Plugin Adavnced Video embed Local File Inclusion (1.0)
WordPress 3.9.x Arbitrary File Deletion Vulnerability (3.9 - 3.9.24)