CVE-2023-49234

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.
Configurations

No configuration.

History

27 Mar 2025, 18:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
CWE CWE-611

21 Nov 2024, 08:33

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Apr/3 - () http://seclists.org/fulldisclosure/2024/Apr/3 -
References () https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-006.txt - () https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-006.txt -
References () https://www.schutzwerk.com/blog/schutzwerk-sa-2023-006/ - () https://www.schutzwerk.com/blog/schutzwerk-sa-2023-006/ -
References () https://www.visual-planning.com/en/support-portal/updates - () https://www.visual-planning.com/en/support-portal/updates -

05 Apr 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad de entidad externa XML (XXE) en Stilog Visual Planning 8. Permite a un atacante autenticado acceder a archivos del servidor local y filtrar datos a un servidor externo.
References
  • () http://seclists.org/fulldisclosure/2024/Apr/3 -

29 Mar 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-29 17:15

Updated : 2025-03-27 18:17


NVD link : CVE-2023-49234

Mitre link : CVE-2023-49234

CVE.ORG link : CVE-2023-49234


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference