Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-25312

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Any23 2.7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.8%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2022-25312
  • Apache » Any23 » Version: 0.2
    cpe:2.3:a:apache:any23:0.2
  • Apache » Any23 » Version: 0.2.1
    cpe:2.3:a:apache:any23:0.2.1
  • Apache » Any23 » Version: 0.2.2
    cpe:2.3:a:apache:any23:0.2.2
  • Apache » Any23 » Version: 0.3.0
    cpe:2.3:a:apache:any23:0.3.0
  • Apache » Any23 » Version: 0.4.0
    cpe:2.3:a:apache:any23:0.4.0
  • Apache » Any23 » Version: 0.4.1
    cpe:2.3:a:apache:any23:0.4.1
  • Apache » Any23 » Version: 0.5.0
    cpe:2.3:a:apache:any23:0.5.0
  • Apache » Any23 » Version: 0.6.0
    cpe:2.3:a:apache:any23:0.6.0
  • Apache » Any23 » Version: 0.6.1
    cpe:2.3:a:apache:any23:0.6.1
  • Apache » Any23 » Version: 0.7.0
    cpe:2.3:a:apache:any23:0.7.0
  • Apache » Any23 » Version: 0.8.0
    cpe:2.3:a:apache:any23:0.8.0
  • Apache » Any23 » Version: 0.9.0
    cpe:2.3:a:apache:any23:0.9.0
  • Apache » Any23 » Version: 1.0
    cpe:2.3:a:apache:any23:1.0
  • Apache » Any23 » Version: 1.1
    cpe:2.3:a:apache:any23:1.1
  • Apache » Any23 » Version: 2.0
    cpe:2.3:a:apache:any23:2.0
  • Apache » Any23 » Version: 2.1
    cpe:2.3:a:apache:any23:2.1
  • Apache » Any23 » Version: 2.2
    cpe:2.3:a:apache:any23:2.2
  • Apache » Any23 » Version: 2.3
    cpe:2.3:a:apache:any23:2.3
  • Apache » Any23 » Version: 2.4
    cpe:2.3:a:apache:any23:2.4
  • Apache » Any23 » Version: 2.5
    cpe:2.3:a:apache:any23:2.5
  • Apache » Any23 » Version: 2.6
    cpe:2.3:a:apache:any23:2.6


Contact Us

Shodan ® - All rights reserved