CVE Published: 24/01/2024 |
CVE Updated: 10/09/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: Ministry of Defense |
Product: Electronic Deliverables Creation Support Tool (Construction Edition) Status : PUBLISHED
CVE-2024-21796 Description
Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.