VendorsCharlesproxycharlesall versions
Vulnerabilities

Charlesproxy Charles

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-19244
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
Published 2018-11-13 · Modified
8.6EPSS 0.020
CVE-2017-15358
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.
Published 2018-08-03 · Modified
7.01 PoCEPSS 0.008