PT-2024-10224 · Unknown · Web Designer

Published

2024-12-11

·

Updated

2025-02-12

·

CVE-2024-12476

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
The Web Designer configuration tool is affected by an Improper Restriction of XML External Entity Reference issue, which could lead to information disclosure, impact workstation integrity, and potentially allow remote code execution on the compromised computer. This occurs when a specifically crafted XML file is imported into the tool. An exploit for this issue is available. The vulnerable software is Web Designer, but the specific versions that are vulnerable are not provided in the given information. However, it's clear that the issue poses a significant risk, including potential remote code execution, and thus should be addressed promptly. #WebDesigner #XMLExternalEntity #InformationDisclosure #RemoteCodeExecution #Cybersecurity #CWE611

Fix

RCE

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-00557
CVE-2024-12476

Affected Products

Web Designer