CVE Vulnerabilities

CVE-2023-49967

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Published: Dec 07, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

Weakness

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Software

NameVendorStart VersionEnd Version
TypechoTypecho1.2.1 (including)1.2.1 (including)
TypechoTypecho1.2.1-rc (including)1.2.1-rc (including)
TypechoTypecho1.2.1-rc2 (including)1.2.1-rc2 (including)

Potential Mitigations

References