An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Jun 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rws
Rws worldserver |
|
| CPEs | cpe:2.3:a:rws:worldserver:11.8.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Rws
Rws worldserver |
Tue, 19 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-611 | |
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-18T00:00:00.000Z
Updated: 2025-10-20T15:42:42.861Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50848
Updated: 2024-11-19T15:04:20.011Z
Status : Modified
Published: 2024-11-18T21:15:06.293
Modified: 2025-10-20T16:15:35.437
Link: CVE-2024-50848
No data.