Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21796

Опубликовано: 24 янв. 2024
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dfeg:electronic_deliverables_creation_support_tool:*:*:*:*:*:construction:*:*
Версия до 1.0.4 (исключая)
cpe:2.3:a:dfeg:electronic_deliverables_creation_support_tool:*:*:*:*:*:design_\&_survey:*:*
Версия до 1.0.4 (исключая)

EPSS

Процентиль: 5%
0.00021
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 5.5
github
около 2 лет назад

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

EPSS

Процентиль: 5%
0.00021
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-611
CWE-611