cvedb.io
CVE-2018-12243
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2018-09-19T15:29:19.217 · Last modified 2026-06-17T01:37:24.900

Summary

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

Affected products

symantec — messaging_gateway

Does this affect you?

Add your gear to cvedb and we'll alert you only when symantec ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.