mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
846 B
846 B
CVE-2021-37425
Description
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
POC
Reference
- http://seclists.org/fulldisclosure/2021/Aug/12
- https://www.redteam-pentesting.de/advisories/rt-sa-2021-002
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses
Github
No PoCs found on GitHub currently.