CVE-2023-46502

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.15 % (51th)
0.15% Progress
Affected Products 1
Advisories 1
NVD Status Modified

An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.

Weaknesses
CWE-611
Improper Restriction of XML External Entity Reference
CWE-918
Server-Side Request Forgery (SSRF)
CVE Status
PUBLISHED
NVD Status
Modified
CNA
MITRE
Published Date
2023-10-30 23:15:08
(10 months ago)
Updated Date
2024-09-09 21:35:01
(9 days ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Opencrx 5.2.2 cpe:2.3:a:opencrx:opencrx:5.2.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...