M
SN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.
References
Configurations
No configuration.
History
12 Feb 2026, 15:10
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 21:16
Updated : 2026-02-12 15:10
NVD link : CVE-2020-37192
Mitre link : CVE-2020-37192
CVE.ORG link : CVE-2020-37192
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference