Description
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
CWE-502 Deserialization of Untrusted Data
Product status
Any version before v4.3.0
Credits
TITAN Team (titancaproject@gmail.com)
References
github.com/datavane/tis/pull/443