Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.00352 Percentile:
0.56883
CVSS Scoring
CVSS v3.1 Score: 9.1
Severity: CRITICAL
Mapped CWE(s)
CWE-611
: Improper Restriction of XML External Entity Reference
All CAPEC(s)
CAPEC-221: Data Serialization External Entities Blowup