e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
History

Tue, 29 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-11-06T01:25:12.005Z

Updated: 2024-10-29T19:03:40.085Z

Reserved: 2023-10-27T00:30:24.289Z

Link: CVE-2023-46802

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.701Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T02:15:07.333

Modified: 2024-11-21T08:29:20.250

Link: CVE-2023-46802

cve-icon Redhat

No data.