Home
LOW: 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LDefault status
unknown
Any version
affected
Description
VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.
Problem types
CWE-674 Uncontrolled Recursion
Product status
Any version
References
github.com/Gelcon/PoC-of-VisiCut2_1-Stack-Overflow-Vul