Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-827c-2vm3-7rqg

Опубликовано: 01 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

EPSS

Процентиль: 34%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
nvd
больше 3 лет назад

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

EPSS

Процентиль: 34%
0.00138
Низкий

8.6 High

CVSS3

Дефекты

CWE-611