When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-04-01T22:17:24.599900Z

Updated: 2024-09-17T04:24:07.507Z

Reserved: 2022-03-17T00:00:00

Link: CVE-2022-1018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-01T23:15:12.177

Modified: 2022-04-12T16:08:19.120

Link: CVE-2022-1018

cve-icon Redhat

No data.