Lucene search

K
cvelistJpcertCVELIST:CVE-2023-27527
HistoryMay 10, 2023 - 12:00 a.m.

CVE-2023-27527

2023-05-1000:00:00
jpcert
www.cve.org
shinseiyo sogo soft
xml
xxe
vulnerability
cve-2023-27527
file access
pc

0.002 Low

EPSS

Percentile

61.0%

Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.

CNA Affected

[
  {
    "vendor": "The Ministry of Justice",
    "product": "Shinseiyo Sogo Soft",
    "versions": [
      {
        "version": "(7.9A) and earlier",
        "status": "affected"
      }
    ]
  }
]

0.002 Low

EPSS

Percentile

61.0%

Related for CVELIST:CVE-2023-27527