
CVE-2020-37192 MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attacke… https://www.cve.org/CVERecord?id=CVE-2020-37192
Post summary
The post announces that MSN Password Recovery 1.30 has an XML external entity injection flaw that allows local file reads, but provides no proof of exploitation, tools, or remediation.
