Description
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36878 | XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker. |
References
History
Mon, 28 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-28T15:02:48.513Z
Reserved: 2023-05-11T04:09:45.906Z
Link: CVE-2023-32635
Updated: 2024-08-02T15:25:35.706Z
Status : Modified
Published: 2023-07-19T06:15:12.787
Modified: 2024-11-21T08:03:44.697
Link: CVE-2023-32635
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD