# CVE-2018-18980 ## XSS vulnerability ## Vulnerability Details | Field | Details | |---|---| | Impact | **CVSS V3 rating: 10 (Critical)** | | Reported | 10 Sept 2018 | | Fixed | 10 Oct 2018 | | Affected Builds | Till Build 123208 | | Fixed in | Build 123214 | | Overview | XML External Entity in Business view page. | | Recommended Fix | **Upgrade to [OpManager Version 12.3.239](https://www.manageengine.com/network-monitoring/service-packs.html) or above.** | ## Description A XML External Entity injection (XXE) vulnerability was discovered in OpManager before version 12.3.214. This vulnerability occurred via the `RequestXML` parameter in a `/devices/ProcessRequest.do` GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server. We recommend that you [upgrade to OpManager Version 12.3.214](https://www.manageengine.com/network-monitoring/service-packs.html) or above to fix this issue. ## Source and Acknowledgements Find out more about CVE-2018-18980 from the [CVE dictionary](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18980). ## Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/network-monitoring/support.html) or email us at [opmanager-support@manageengine.com](mailto:opmanager-support@manageengine.com).