Loading
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Use CWE-611, Sugarcrm vendor hub and Sugarcrm product page to widen CVE-2014-3244 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-22952, CVE-2020-7472 and CVE-2023-46816 for nearby disclosures in the same product family.