CVE-2018-1000829 Information
Feb 14, 2021
cve
Description
Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Disclosure of confidential data denial of service SSRF port scanning. This vulnerability appears to have been fixed in after commit 80359b4.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Reference
https://0dd.zone/2018/10/28/anyplace-XXE-MitM/ https://github.com/dmsl/anyplace/issues/263
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.0
Share on: