Loading vulnerability details…
CVSS v3.1
N/A
EPSS
21.07%
Published
Nov 2, 2013
Modified
Apr 28, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
Weaknesses (CWE)
Affected Products (3)
References (6)