Description
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
Remediation
References
https://0dd.zone/2018/10/28/xr3player-XXE/
https://github.com/goxr3plus/XR3Player/issues/9
Related Vulnerabilities
CVE-2022-45395 Vulnerability in maven package com.thalesgroup.jenkins-ci.plugins:cccc
CVE-2022-37616 Vulnerability in npm package @xmldom/xmldom
CVE-2020-10969 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-27405 Vulnerability in npm package @progfay/scrapbox-parser
CVE-2023-0674 Vulnerability in maven package com.xuxueli:xxl-job-core