Description
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-0440 Vulnerability (CVE-2013-0440)
WordPress Plugin MailPoet-emails and newsletters in WordPress Cross-Site Scripting (3.23.1)
WordPress Plugin Omni Secure Files 'upload.php' Arbitrary File Upload (0.1.13)
Jboss EAP Other Vulnerability (CVE-2019-9513)
WordPress Plugin Login as User or Customer Security Bypass (1.7)