silverstripeCMS Improper Restriction of Recursive Entity References in DTDs (XML Entity Expansion) Vulnerability - CVE-2021-41559 - Vulnerability Database
silverstripeCMS Improper Restriction of Recursive Entity References in DTDs (XML Entity Expansion) Vulnerability - CVE-2021-41559
Medium
Reference:
CVE-2021-41559
Title:
silverstripeCMS Improper Restriction of Recursive Entity References in DTDs (XML Entity Expansion) Vulnerability
Overview:
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.