Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-8940

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-8940
  • Enghouse » Contact Center » Version: _service_provider
    cpe:2.3:a:enghouse:contact_center:_service_provider


Contact Us

Shodan ® - All rights reserved