Description
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4283)
WordPress 2.6.1 Lost Password SQL Column Truncation Unauthorized Access Vulnerability (0.71 - 2.6.1)
WordPress Plugin WordPress Poll Cross-Site Request Forgery (34.05)
WordPress Plugin Intuitive Custom Post Order Multiple Vulnerabilities (3.1.3)
PHP Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2020-7070)