peter bassill · operator
$ cve CVE-2013-3617 JSON

CVE-2013-3617 EXPLOIT

3.5
LOW · CVSS 2.0 · EPSS 21.1% (pctl 98)

Patch early

A public exploit exists.

Description

The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

Scoring

CVSS3.5 (LOW, v2.0)
VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS21.07% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2013-11-02
Last modified2026-06-16

Affected (1)

VendorProduct
openbravoopenbravo erp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD