PT-2024-13703 · Stilog · Stilog Visual Planning
David Brown
+1
·
Published
2024-03-29
·
Updated
2025-03-27
·
CVE-2023-49234
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Stilog Visual Planning version 8
Description
An XML external entity (XXE) vulnerability was found in the software. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.
Recommendations
For Stilog Visual Planning version 8, consider disabling XML external entities or restricting access to sensitive files as a temporary workaround until a patch is available.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stilog Visual Planning