PT-2023-18470 · Unknown · Tsclinical Metadata Desktop Tools+1

Sakaki Ryutaro

+1

·

Publicado

2023-02-15

·

Atualizado

2025-03-19

·

CVE-2023-22377

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions tsClinical Define.xml Generator versions 1.0.0 through 1.4.0 tsClinical Metadata Desktop Tools versions 1.0.3 through 1.1.0
Description An improper restriction of XML external entity reference (XXE) issue exists, allowing an attacker to obtain an arbitrary file by reading a specially crafted XML file if the vulnerability is exploited.
Recommendations For tsClinical Define.xml Generator versions 1.0.0 through 1.4.0, update to a version that addresses the XXE vulnerability. For tsClinical Metadata Desktop Tools versions 1.0.3 through 1.1.0, update to a version that addresses the XXE vulnerability. As a temporary workaround, consider restricting the use of XML external entities in the affected software until a patch is available.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22377

Produtos afetados

Tsclinical Define.Xml Generator
Tsclinical Metadata Desktop Tools