XML External Entity vulnerability in map parser

From Freeplane - free mind mapping and knowledge management software
Revision as of 11:09, 23 April 2017 by Dimitry (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Reported on 2017/02/19

Fix released on 2017/04/15

Reported by Wojciech Reguła, https://www.linkedin.com/in/wojciech-regula/

Description of Vulnerability

The vulnerability allowed to download any file from victim's computer when the victim opens the malicious mindmap. The vulnerability pattern is described at https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing.