TROYANOSYVIRUS
Back to CVEs

CVE-2018-10832

N/A

Description

ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

CVE Details

CVSS v3.1 ScoreN/A
Published5/11/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

modbuspal_project:modbuspal

Weaknesses (CWE)

CWE-611

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.