CVE-2018-17289: Kofax Front Office Server
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter.
Affected products
- Kofax Front Office Server: version 4.1.1.11.0.5212 only
Published 2019-04-18. Last modified 2026-06-17.