CVE-2024-45745

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
27/09/2024
Last modified:
22/09/2025

Description

TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:* 8.0.1 (excluding)