GITHUBEXPLOIT 9.8 CRITICAL

Exploit for Improper Restriction of XML External Entity Reference in Geoserver_184C78DE-1DF5-53A2-8049-589E479FD4BF

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

CVE-2025-58360: GeoServer XXE Lab Unauthenticated XML External Entity XXE Injection in GeoServer OWS/WMS Services CVSS: 9.8 CRITICAL Affected: SLDHandler.parse | | - SLDParser.parseSLD | File/SSRF Quick Start bash Start both vulnerable and patched...
Visit Original Source

Basic Information

ID 184C78DE-1DF5-53A2-8049-589E479FD4BF
Published Dec 12, 2025 at 18:51
Modified Dec 12, 2025 at 20:14

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.