CVE-2023-26559
Published Apr 14, 2023
Last updated 2 years ago
Overview
- Description
- A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sync:oxygen_content_fusion:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7594B8B-6BA1-4F9B-87A2-C35DBB9A4798", "versionEndExcluding": "5.0.3" }, { "criteria": "cpe:2.3:a:sync:oxygen_xml_web_author:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63D2AEBF-3EF4-4EC9-8349-E5BB28605065", "versionEndExcluding": "23.1.1.4" }, { "criteria": "cpe:2.3:a:sync:oxygen_xml_web_author:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12117098-405D-4342-A7CA-5CD709206F61", "versionEndExcluding": "24.1.0.3", "versionStartIncluding": "24.0.0.0" }, { "criteria": "cpe:2.3:a:sync:oxygen_xml_web_author:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13437A78-B667-487C-B5A2-DCBF966E09EB", "versionEndExcluding": "25.1.0.3", "versionStartIncluding": "25.0.0.0" } ], "operator": "OR" } ] } ]