PT-2024-14500 · Magic · Magic Xpi Integration Platform

Published

2024-02-06

·

Updated

2024-02-13

·

CVE-2023-52239

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Magic xpi Integration Platform version 4.13.4
Description The XML parser in Magic xpi Integration Platform allows XXE attacks, for example, via onItemImport.
Recommendations For Magic xpi Integration Platform version 4.13.4, consider disabling the XML parser or restricting its use until a patch is available. As a temporary workaround, avoid using the onItemImport function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Weakness Enumeration

Related Identifiers

CVE-2023-52239

Affected Products

Magic Xpi Integration Platform