CVE-2025-11700
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-12
Last updated on: 2025-12-15
Assigner: N-able
Description
Description
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| n-able | n-central | to 2025.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an XML External Entities (XXE) injection in N-central versions prior to 2025.4. It allows an attacker to exploit the XML parser to disclose sensitive information from the system.
How can this vulnerability impact me? :
The vulnerability can lead to information disclosure, potentially exposing sensitive data to unauthorized parties, which could compromise system confidentiality and security.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70