Impact
CyberELF NanoXML version 2.2.3 contains an XML External Entity injection vulnerability. The API parses XML input with external entity support enabled by default, allowing a well‑formed XML document to reference resources external to the parser. The CVE notes only information disclosure as the impact, indicating that confidential data could be read via the XML payload.
Affected Systems
The affected product is CyberELF NanoXML, version 2.2.3. No other vendors or versions are mentioned.
Risk and Exploitability
The CVSS base score of 5.3 places this issue at medium severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. This vulnerability is not listed in the CISA KEV catalog. If the service that exposes the NanoXML API accepts untrusted input, an attacker could exploit the XXE flaw by providing crafted XML. Defenses include disabling external entity processing or otherwise sanitizing input.
OpenCVE Enrichment