Description
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.
Remediation
References
https://0dd.zone/2018/10/28/bw-calendar-engine-XXE-MitM/
https://github.com/Bedework/bw-calendar-engine/issues/3
Related Vulnerabilities
CVE-2020-11113 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-23328 Vulnerability in npm package iniparserjs
CVE-2019-14893 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-16330 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap