CVE-2013-3925
Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.
- Affected products
- Crowd
- Atlassian Crowd
- = 2.5.0, 2.5.1, 2.5.2, 2.5.3
- Fix
- Available
- CVSS 2.0
- 5.8 MEDIUM
- EPSS
- 1.8% (76th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2013-07-01
CVE-2013-3925 at NVD
No indexed exploits for CVE-2013-3925 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-3925 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.