CVE-2024-7098

Sept. 16, 2024, 3:30 p.m.

Awaiting Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

ww.Winsure

  • before 4.6.2

Source

iletisim@usom.gov.tr

Tags

CVE-2024-7098 details

Published : Sept. 16, 2024, 3:15 p.m.
Last Modified : Sept. 16, 2024, 3:30 p.m.

Description

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-611 Improper Restriction of XML External Entity Reference The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

References

URL Source
https://www.usom.gov.tr/bildirim/tr-24-1475 iletisim@usom.gov.tr
This website uses the NVD API, but is not approved or certified by it.