### [CVE-2018-1000546](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000546) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML). ### POC #### Reference - https://0dd.zone/2018/05/31/TripleA-XXE/ #### Github No PoCs found on GitHub currently.