CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. Exploitation may require the attacker to be authenticated.
CVE
CVE-2022-26662
Severity
HIGH
CVSS
7.5
EPSS
1.96%
Original NVD Description
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)