Back to search
CVE-2018-1000069
Published: Mar 13, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[debian-lts-announce] 20180324 [SECURITY] [DLA 1316-1] freeplane security update
mailing-list
x_refsource_MLIST
DSA-4175
vendor-advisory
x_refsource_DEBIAN
https://www.youtube.com/watch?v=7IXtiTNilAI
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now