CVE-2025-48006

CRITICAL WAF: High
CVSS 9.1 Published: 2025-09-29
CWE-611

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
saisondataspider_servistaup to 4.4

References

Back to CVE Database