Описание
OpenCRX allows a remote attacker to execute arbitrary code via a crafted request
An issue in OpenCRX v.5.2.2 allows a remote attacker to execute arbitrary code via a crafted request.
Пакеты
Наименование
org.opencrx:opencrx-client
maven
Затронутые версииВерсия исправления
< 5.3.0
5.3.0
Связанные уязвимости
CVSS3: 9.8
nvd
больше 2 лет назад
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.