CVE-2018-14473: Ocsinventory-NG Ocsinventory NG
Critical severity, CVSS 9.1. EPSS: 3.1% chance of exploitation in the next 30 days.
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
Affected products
- Ocsinventory-NG Ocsinventory NG: version 2.4.1 only
Published 2018-08-04. Last modified 2026-06-17.