CVE-2017-17762: Episerver

High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.

Affected products

  • Episerver Episerver: up to and including 7; version 7 only

Published 2018-08-29. Last modified 2026-06-17.