Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2021-43306 Vulnerability in maven package org.webjars.npm:jquery-validation
CVE-2019-10424 Vulnerability in maven package com.technicolor:eloyente
CVE-2018-1000068 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-15149 Vulnerability in npm package nodebb
CVE-2021-27578 Vulnerability in maven package org.apache.zeppelin:zeppelin