-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from XML parsing in document type import functionality. The patch adds 'xd.XmlResolver = null' to both methods, indicating they previously used the default XmlResolver which processes external entities. These event handlers load XML from user-controlled files without proper restrictions, making them entry points for XXE attacks. The direct correlation between the vulnerability description and the patched code confirms these functions' role.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| UmbracoCms.Web | nuget | < 7.7.3 | 7.7.3 |
KEV Misses 88% of Exploited CVEs- Get the report