Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j86-qhx5-3qv8

Опубликовано: 23 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

EPSS

Процентиль: 11%
0.00036
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

EPSS

Процентиль: 11%
0.00036
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611