Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2019-10423 Vulnerability in maven package com.villagechief.codescan.jenkins:codescan
CVE-2018-1305 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-10367 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2019-1003096 Vulnerability in maven package org.jenkins-ci.plugins:testfairy