CVE Published: 06/11/2023 |
CVE Updated: 29/10/2024 |
CVE Year: 2023 Source: jpcert |
Vendor: National Tax Agency |
Product: e-Tax software Status : PUBLISHED
CVE-2023-46802 Description
e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.