Vulnerabilities (CVE)

Filtered by vendor Ocsinventory-ng Subscribe
Filtered by product Ocsinventory Ng
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14473 1 Ocsinventory-ng 1 Ocsinventory Ng 2018-10-01 6.4 MEDIUM 9.1 CRITICAL
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.