CVE-2020-9352 describes a critical blind XML External Entity (XXE) vulnerability in SmartClient 12.0's developer console, specifically within the downloadWSDL feature. This flaw allows unauthenticated attackers to send a crafted POST request to /tools/developerConsoleOperations.jsp, potentially leading to full compromise of confidentiality, integrity, and availability. While the vendor notes these tools should be restricted, the vulnerability has a CVSS score of 9.8 (Critical) due to its network-based, low-complexity attack vector requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low immediate threat despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0CPE matchmatch criteria | cpe:2.3:a:smartclient:smartclient:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.