Skip to main content
CRITICAL

CVE-2018-8940

CVSS v3

9.8

CRITICAL

EPSS Score

1.6 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

Technical details

Published
2019-05-14

Frequently asked questions

What is CVE-2018-8940?

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue.

Is CVE-2018-8940 actively exploited?

Active exploitation of CVE-2018-8940 has not been confirmed. Its EPSS score was 1.6% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-8940?

CVE-2018-8940 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-8940 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key