XML-RPC.NET.pingback.XXE

description-logoDescription

This indicates an attack attempt to exploit an External Entity Injection Vulnerability in XML-RPC.NET.
The vulnerability is caused by improper parsing and sanitation on XML data posted to a pingback endpoint on a server running XML-RPC.NET. An authenticated attacker can exploit this with a constructed payload to enumerate and exfiltrate files on the server.

affected-products-logoAffected Products

XML-RPC.NET versions prior to 2.5.0

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the website.
https://code.google.com/archive/p/xmlrpcnet/downloads

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-04-14 27.767 Default_action:pass:drop
2024-04-03 27.760