mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 22:53:11 +00:00
857 B
857 B
CVE-2021-37425
Description
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
POC
Reference
- http://seclists.org/fulldisclosure/2021/Aug/12
- https://www.redteam-pentesting.de/advisories/rt-sa-2021-002
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses
Github
No PoCs found on GitHub currently.