An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-06-14T02:46:00
Updated: 2024-08-03T07:19:05.696Z
Reserved: 2022-05-23T00:00:00
Link: CVE-2022-31447
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-06-14T03:15:08.240
Modified: 2022-06-27T16:21:33.767
Link: CVE-2022-31447
Redhat
No data.