ETQ Reliance CG XML External Entity (XXE) Injection in SSO SAML Handler

CVE Details

Basic Information

Title ETQ Reliance CG XML External Entity (XXE) Injection in SSO SAML Handler
Type cve
Published 2025-07-22T12:31:58.875Z
Modified 2025-07-22T13:29:08.545Z

Product Information

Vendor ETQ
Product Reliance CG (legacy)
Version *

CVSS Information

Base Score 6.9 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Products

  • ETQ Reliance CG (legacy) *
  • ETQ Reliance CG (legacy) *

Additional Information

CWE List CWE-611
Source VulnCheck

Description

An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side request forgery (SSRF). The issue was addressed by disabling external entity processing for the affected XML parser in versions SE.2025.1 and 2025.1.2.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.