CVE-2012-3488 is a vulnerability in the libxslt support within PostgreSQL's contrib/xml2 component, affecting versions 8.3, 8.4, 9.0, and 9.1. It allows remote authenticated users to bypass access restrictions on files and URLs through stylesheet commands or an xslt_process feature, leading to an XML External Entity (XXE) issue. The vulnerability has a CVSS score of 4.9, indicating medium severity, as it requires authentication and moderate attack complexity, but can result in partial confidentiality and integrity impact, including data modification, information disclosure, or outbound traffic. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog. Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:* | ||
9.1.1CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:* | ||
9.1.2CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:* | ||
9.1.3CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:9.1.3:*:*:*:*:*:*:* | ||
9.1.4CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:9.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.