CVE-2024-45745

Published Sep 27, 2024

Last updated 2 months ago

Overview

Description
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5
Impact score
1.4
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

9119a7d8-5eab-497f-8521-727c672e3725
CWE-611

Social media

Hype score
Not currently trending