Description
Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36882 | Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker. |
References
History
Wed, 23 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-23T19:14:30.185Z
Reserved: 2023-05-11T04:09:45.920Z
Link: CVE-2023-32639
Updated: 2024-08-02T15:25:35.747Z
Status : Modified
Published: 2023-07-25T04:15:10.467
Modified: 2024-11-21T08:03:45.170
Link: CVE-2023-32639
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD