XML External Entity Vulnerability in LemonLDAP::NG by OW2
CVE-2019-13031
8.1HIGH
What is CVE-2019-13031?
LemonLDAP::NG prior to version 1.9.20 contains an XML External Entity (XXE) flaw, which occurs during the submission of notifications to the notification server. Though the server is not activated by default and has stringent 'deny all' rules, this vulnerability could enable attackers to exploit the service in configurations where it is enabled, leading to potential exposure of sensitive information.
