CVE Published: 11/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: Ministry of Land, Infrastructure, Transport and Tourism, Japan |
Product: National land numerical information data conversion tool Status : PUBLISHED
CVE-2023-25955 Description
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.