peter bassill · operator
$ cve CVE-2017-9355 JSON

CVE-2017-9355 EXPLOIT

7.4
HIGH · CVSS 3.0 · EPSS 26.9% (pctl 98)

Patch early

A public exploit exists.

Description

XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.

Scoring

CVSS7.4 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
EPSS26.91% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploityes
Published2017-06-07
Last modified2026-06-17

Affected (1)

VendorProduct
subsonicsubsonic

Public exploits

SourceTitleDate
exploit-dbSubsonic 6.1.1 - XML External Entity Injection2017-06-05

References

→ the Explorer  ·  watch your stack  ·  NVD