ZeroHour

CVE-2021-27777

CVSS 3.1
7.5 high
EPSS
<1%p55
Published
()
Modified
Description

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

Vendors
hcltech
Products
unica
Weakness
CWE-91, CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.