cbcvebase.
CVE-2018-1000069
published 2018-03-13

CVE-2018-1000069: FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from…

PriorityP428medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
2.26%
81.3th percentile
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfreeplane< freeplane 1.6.6-1 (bookworm)freeplane 1.6.6-1 (bookworm)
freeplanefreeplane<= 1.5.9
freeplanefreeplane>= 0 < 1.6.6-11.6.6-1
freeplanefreeplane>= 0 < 1.6.6-11.6.6-1
freeplanefreeplane>= 0 < 1.6.6-11.6.6-1

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.