Vulnerability Database

300,926

Total vulnerabilities in the database

CVE-2018-12243

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

  • Published: Sep 19, 2018
  • Updated: Nov 9, 2025
  • CVE: CVE-2018-12243
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:A/AC:L/Au:N/C:P/I:P/A:P