Description
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are emailed to the address in the rua field of the DMARC records of a domain.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0087 | The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are emailed to the address in the rua field of the DMARC records of a domain. |
Github GHSA |
GHSA-vc42-mgr2-w34r | Modoboa is vulnerable to an XML External Entity Injection (XXE) |
References
| Link | Providers |
|---|---|
| https://github.com/modoboa/modoboa-dmarc/issues/38 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.360Z
Reserved: 2019-12-10T00:00:00.000Z
Link: CVE-2019-19702
No data.
Status : Modified
Published: 2019-12-10T20:15:17.497
Modified: 2024-11-21T04:35:13.300
Link: CVE-2019-19702
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA