e-Tax software Version3.0.10 and earlier improperly...
Moderate severity
Unreviewed
Published
Nov 6, 2023
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Description
Published by the National Vulnerability Database
Nov 6, 2023
Published to the GitHub Advisory Database
Nov 6, 2023
Last updated
Oct 29, 2024
e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
References