rtMedia for WordPress, BuddyPress and bbPress - XML injection (XXE)
Severity pending
Summary
Full name
rtMedia for WordPress, BuddyPress and bbPress 4.6.2 - XML injection (XXE)
Code name
State
Private
Release date
6 dic 2024
Affected product
rtMedia for WordPress, BuddyPress and bbPress
Affected version(s)
Version 4.6.2
Vulnerability name
XML injection (XXE)
Vulnerability type
Remotely exploitable
No
CVSS v4.0 vector string
CVSS:4.0/AV:N/AT:N/AC:L/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Exploit available
No
CVE ID(s)
Description
rtMedia for WordPress, BuddyPress and bbPress 4.6.2 was found to be vulnerable. Access to external entities in XML parsing is enabled in myapp/lib/getid3/getid3.lib.php.
Vulnerability
Skims by Fluid Attacks discovered a XML injection (XXE) in rtMedia for WordPress, BuddyPress and bbPress 4.6.2. The following is the output of the tool:
Skims output
Our security policy
We have reserved the ID CVE-2025-22625 to refer to this issue from now on.
System Information
Version: rtMedia for WordPress, BuddyPress and bbPress 4.6.2
Mitigation
There is currently no patch available for this vulnerability.
Timeline
IA generativa
6 dic 2024
Public disclosure
7 ene 2025