A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The exploit has been disclosed to the public and may be used. VDB-231626 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2023-06-15T13:00:03.622Z

Updated: 2024-08-02T06:48:08.457Z

Reserved: 2023-06-15T12:16:46.960Z

Link: CVE-2023-3276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-06-15T13:15:09.773

Modified: 2024-05-17T02:27:24.320

Link: CVE-2023-3276

cve-icon Redhat

No data.