9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
- During my geoserver analysis I found another way to attack unauthenticated XML External Entities XXE via WMS GetMap operation. We can call this vulnerability via /geoserver/workspaces/ows, by using OWS call to WMS service instead of calling WMS...
Basic Information
ID
EFE8D5A5-DDF1-5B89-BE33-B6CCAF3B4E93
Published
Dec 31, 2025 at 03:49
Modified
Dec 31, 2025 at 03:55