Required CVE Record Information
Description
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.1 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
References 1 Total
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0007 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0007 vendor-advisoryx_transferred