GHSA-m3cm-h6wg-q547
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 26, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.