CVE Published: 19/07/2023 |
CVE Updated: 28/10/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: Financial Services Agency |
Product: XBRL data create application Status : PUBLISHED
CVE-2023-32635 Description
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.