Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Simon Napper 113 posts 347 karma points
    Sep 06, 2016 @ 13:45
    Simon Napper
    0

    XML External Entities Injection Vulnerability

    Hi,

    I've had a client ask me today if their version of Umbraco (6.2.5) is suspectible to an XML External Entities Injection attack? Although I'm sure this has been handled, according to OWASP there is a risk if the version of .Net is below 4.6 (https://www.owasp.org/index.php/XMLExternalEntity(XXE)Processing) so does anyone know for sure if this is something that is definitely handled by Umbraco version 6.2.5?

    Cheers,

    Simon

Please Sign in or register to post replies

Write your reply to:

Draft