Description
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Remediation
References
Related Vulnerabilities
WordPress Plugin EMC2 Custom Help Videos Cross-Site Scripting (1.2)
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (4.6.12)
TYPO3 Improper Input Validation Vulnerability (CVE-2013-4250)
Apache HTTP Server Insufficient Verification of Data Authenticity Vulnerability (CVE-2022-31813)