CBRN-Analysis before 22 allows XXE attacks via am mws XML...
Moderate severity
Unreviewed
Published
Nov 12, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Nov 12, 2022
Published to the GitHub Advisory Database
Nov 12, 2022
Last updated
Jan 28, 2023
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
References