A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The exploit has been disclosed to the public and may be used. VDB-231626 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 21 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2023-06-15T13:00:03.622Z

Updated: 2024-11-21T16:06:12.623Z

Reserved: 2023-06-15T12:16:46.960Z

Link: CVE-2023-3276

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.457Z

cve-icon NVD

Status : Modified

Published: 2023-06-15T13:15:09.773

Modified: 2024-11-21T08:16:54.930

Link: CVE-2023-3276

cve-icon Redhat

No data.