GITHUBEXPLOIT 9.8 CRITICAL

Exploit for Improper Restriction of XML External Entity Reference in Geoserver_EFE8D5A5-DDF1-5B89-BE33-B6CCAF3B4E93

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

- During my geoserver analysis I found another way to attack unauthenticated XML External Entities XXE via WMS GetMap operation. We can call this vulnerability via /geoserver/workspaces/ows, by using OWS call to WMS service instead of calling WMS...
Visit Original Source

Basic Information

ID EFE8D5A5-DDF1-5B89-BE33-B6CCAF3B4E93
Published Dec 31, 2025 at 03:49
Modified Dec 31, 2025 at 03:55

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.