CVE-2022-32458

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
20/07/2022
Last modified:
14/09/2022

Description

Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digiwin:business_process_management:*:*:*:*:*:*:*:* 5.8.8.1 (excluding)