Sploitus

CVE-2013-3925

No indexed exploits for CVE-2013-3925 yet

Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.

Affected products
Crowd
Atlassian Crowd
= 2.5.0, 2.5.1, 2.5.2, 2.5.3
Fix
Available
CVSS 2.0
5.8 MEDIUM
EPSS
1.8% (76th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2013-07-01
CVE-2013-3925 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2013-3925 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2013-3925 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.