ZeroHour

CVE-2021-28684

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p58
Published
()
Modified
Description

The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).

Vendors
powerarchiver
Products
powerarchiver
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.