CVE-2021-28684
PoC —CVSS 3.1
4.3 medium
EPSS
<1%p58
Published
()
Modified
Description
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
- Vendors
- powerarchiver
- Products
- powerarchiver
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.