Vulnerability CVE-2023-28150


Published: 2023-03-24   Modified: 2023-03-25

Description:
An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.

 References:
https://www.independentsoft.de/jword/index.html
https://excellium-services.com/cert-xlm-advisory/CVE-2023-28150

Copyright 2024, cxsecurity.com

 

Back to Top