CVE-2023-38490 is a critical XML External Entity (XXE) vulnerability affecting Kirby CMS versions prior to 3.9.6, specifically when custom site or plugin code utilizes the Xml data handler or Xml::parse() method. With a CVSS score of 10.0, this vulnerability allows unauthenticated attackers to achieve arbitrary file disclosure or Server-Side Request Forgery (SSRF) by injecting external entities into XML files processed by vulnerable Kirby installations. While not actively exploited in the wild and lacking public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.8.3CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.6.6.3CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* | ||
>= 3.7.0, < 3.7.5.2CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.4.1CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.6CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.