An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.
References
Configurations
No configuration.
History
27 Mar 2025, 18:17
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
CWE | CWE-611 |
21 Nov 2024, 08:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/Apr/3 - | |
References | () https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-006.txt - | |
References | () https://www.schutzwerk.com/blog/schutzwerk-sa-2023-006/ - | |
References | () https://www.visual-planning.com/en/support-portal/updates - |
05 Apr 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
29 Mar 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-29 17:15
Updated : 2025-03-27 18:17
NVD link : CVE-2023-49234
Mitre link : CVE-2023-49234
CVE.ORG link : CVE-2023-49234
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference