Description
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:49:24.692Z
Reserved: 2019-07-05T00:00:00.000Z
Link: CVE-2019-13358
No data.
Status : Modified
Published: 2019-07-05T21:15:10.730
Modified: 2024-11-21T04:24:47.250
Link: CVE-2019-13358
No data.
OpenCVE Enrichment
No data.
Weaknesses