Description
e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50968 | e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker. |
References
History
Tue, 29 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-29T19:03:40.085Z
Reserved: 2023-10-27T00:30:24.289Z
Link: CVE-2023-46802
Updated: 2024-08-02T20:53:21.701Z
Status : Modified
Published: 2023-11-06T02:15:07.333
Modified: 2024-11-21T08:29:20.250
Link: CVE-2023-46802
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD