PT-2023-31790 · Topografix · Topografix Dataplugin For Gpx

Kimiya

·

Published

2023-11-08

·

Updated

2024-10-10

·

CVE-2023-5136

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TopoGrafix DataPlugin for GPX (affected versions not specified)
Description An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this issue by getting a user to open a specially crafted data file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

XXE

Weakness Enumeration

Related Identifiers

CVE-2023-5136
ZDI-23-1622

Affected Products

Topografix Dataplugin For Gpx