CVE-2013-3617 EXPLOIT
3.5
LOW · CVSS 2.0 · EPSS 21.1% (pctl 98)
Patch early
A public exploit exists.
Description
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
Scoring
| CVSS | 3.5 (LOW, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
| EPSS | 21.07% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-11-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| openbravo | openbravo erp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Openbravo ERP - XML External Entity Information Disclosure | 2013-10-30 |
References
- http://www.kb.cert.org/vuls/id/533894
- http://www.securityfocus.com/bid/63431
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
- http://www.kb.cert.org/vuls/id/533894
- http://www.securityfocus.com/bid/63431
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
→ the Explorer · watch your stack · NVD