Sploitus

CVE-2019-9757

1 known exploit for CVE-2019-9757

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

Affected products
Labkey Server
Labkey Labkey Server
= 19.1.0
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
37.3% (98th percentile)
Weakness
CWE-611
NVD status
Modified
Published
2019-10-29
CVE-2019-9757 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2019-9757

Proof-of-concept code and exploit modules indexed by Sploitus