Description


TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).

Related CPE's


Weaknesses


9119a7d8-5eab-497f-8521-727c672e3725

Secondary

CWE-611

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

5 · Medium

Information


Source identifier

9119a7d8-5eab-497f-8521-727c672e3725

Vulnerability status

Analyzed

Published

2024-09-27T14:15:05.037Z

1 year ago

Last modified

2025-09-22T15:17:23.523Z

6 months ago