CVE-2023-1288

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
09/03/2023
Last modified:
07/11/2023

Description

<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:3ds:enovia_live_collaboration:*:*:*:*:*:*:*:* v6r2013xe (including) v6r2013xe_fp.cfa.2240 (excluding)


References to Advisories, Solutions, and Tools