CVE Vulnerabilities

CVE-2019-13176

Improper Restriction of XML External Entity Reference

Published: Aug 08, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
3cx 3cx 12.5-sp1 (including) 12.5-sp1 (including)
3cx 3cx 12.5-sp2 (including) 12.5-sp2 (including)
3cx 3cx 12.5.44178.1002 (including) 12.5.44178.1002 (including)

Potential Mitigations

References