CVE Published: 10/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: The Ministry of Justice |
Product: Shinseiyo Sogo Soft Status : PUBLISHED
CVE-2023-27527 Description
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.