Home
MEDIUM: 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NDefault status
unknown
Any version before 8.0.1
affected
8.0.1
unaffected
Description
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version before 8.0.1
8.0.1
References
raw.githubusercontent.com/...IT/white/2024/va-24-254-02.json (url)
www.topquadrant.com/...t/uploads/2024/06/changelog-8.0.1.txt (url)