Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63vx-fx7j-2x6p

Опубликовано: 02 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

EPSS

Процентиль: 8%
0.00028
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

EPSS

Процентиль: 8%
0.00028
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611