CVE Published: 02/10/2023 |
CVE Updated: 20/09/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: Ministry of Health, Labour and Welfare |
Product: FD Application Status : PUBLISHED
CVE-2023-42132 Description
FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.