Vulnerabilities (CVE)

Filtered by vendor Smartclient Subscribe
Filtered by product Smartclient
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9352 1 Smartclient 1 Smartclient 2021-07-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter.