CVE-2018-20298: s3browser s3 Browser
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
Affected products
- s3browser s3 Browser: before 8.1.5 (fixed in 8.1.5)
Published 2018-12-19. Last modified 2026-06-17.