XML Quadratic Blowup Vulnerability in Typecho Product by Typecho
CVE-2023-49967
7.5HIGH
What is CVE-2023-49967?
Typecho version 1.2.1 is susceptible to an XML Quadratic Blowup attack through the /index.php/action/xmlrpc endpoint. This vulnerability can be exploited by malicious actors to cause significant resource consumption, potentially leading to a denial of service by overwhelming the server with excessive data processing. Users of this version are urged to apply security measures immediately to safeguard their systems.
