Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43624

Опубликовано: 23 окт. 2023
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:omrom:cx-designer:*:*:*:*:*:*:*:*
Версия до 3.740 (включая)

EPSS

Процентиль: 11%
0.00036
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 5.5
github
больше 2 лет назад

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

EPSS

Процентиль: 11%
0.00036
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611