CVSS Rating: 6.5 (low)
Disclosing Company: Rhino Security Labs
Date: 01/17/2018
Status: Published
Affected software/version:Aurea Jive Jive-n 9.0.2.1 On-Premises
Blog Post: XML External Entity Injection in Jive-n (CVE-2018-5758)
MITRE
NIST
01/17/2018
The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files.
6.5 (Low)