Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://github.com/goxr3plus/XR3Player/issues/9
https://0dd.zone/2018/10/28/xr3player-XXE/
Related Vulnerabilities
CVE-2021-44906 Vulnerability in npm package minimist
CVE-2021-27516 Vulnerability in npm package urijs
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp
CVE-2019-10379 Vulnerability in maven package org.jenkins-ci.plugins:gcm-notification
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-markdown-gfm