CVE-2017-13706
Description
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| lansweeper | lansweeper | {"endIncluding":"6.0.100.29"} | |
References
- http://packetstormsecurity.com/files/144527/Lansweeper-6.0.100.29-XXE-Injection.html
- http://seclists.org/fulldisclosure/2017/Oct/14
- https://www.lansweeper.com/changelog.aspx
- http://packetstormsecurity.com/files/144527/Lansweeper-6.0.100.29-XXE-Injection.html
- http://seclists.org/fulldisclosure/2017/Oct/14
- https://www.lansweeper.com/changelog.aspx
CWEs
CWE-611
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.