PT-2023-18470 · Unknown · Tsclinical Metadata Desktop Tools+1
Sakaki Ryutaro
+1
·
Publicado
2023-02-15
·
Atualizado
2025-03-19
·
CVE-2023-22377
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
tsClinical Define.xml Generator versions 1.0.0 through 1.4.0
tsClinical Metadata Desktop Tools versions 1.0.3 through 1.1.0
Description
An improper restriction of XML external entity reference (XXE) issue exists, allowing an attacker to obtain an arbitrary file by reading a specially crafted XML file if the vulnerability is exploited.
Recommendations
For tsClinical Define.xml Generator versions 1.0.0 through 1.4.0, update to a version that addresses the XXE vulnerability.
For tsClinical Metadata Desktop Tools versions 1.0.3 through 1.1.0, update to a version that addresses the XXE vulnerability.
As a temporary workaround, consider restricting the use of XML external entities in the affected software until a patch is available.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tsclinical Define.Xml Generator
Tsclinical Metadata Desktop Tools