PT-2024-10224 · Unknown · Web Designer
Published
2024-12-11
·
Updated
2025-02-12
·
CVE-2024-12476
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
The Web Designer configuration tool is affected by an Improper Restriction of XML External Entity Reference issue, which could lead to information disclosure, impact workstation integrity, and potentially allow remote code execution on the compromised computer. This occurs when a specifically crafted XML file is imported into the tool.
An exploit for this issue is available.
The vulnerable software is Web Designer, but the specific versions that are vulnerable are not provided in the given information.
However, it's clear that the issue poses a significant risk, including potential remote code execution, and thus should be addressed promptly.
#WebDesigner #XMLExternalEntity #InformationDisclosure #RemoteCodeExecution #Cybersecurity #CWE611
Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Designer