CVE-2021-38490
Published Aug 10, 2021Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
Vendor/product archive
2 CVEs tagged to altova / mobiletogether_server — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then…