CVE-2017-1000021: XEE
Published Jul 13, 2017
·Updated
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
Affected Software
1 affected component
LogicalDOC LogicalDOC<=7.5.3
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000021?
CVE-2017-1000021 is classified as a medium severity vulnerability due to its potential for exploitation via XXE attacks.
2
How do I fix CVE-2017-1000021?
To fix CVE-2017-1000021, upgrade LogicalDoc Community Edition to version 7.5.4 or later to mitigate the XXE vulnerability.
3
What type of vulnerability is CVE-2017-1000021?
CVE-2017-1000021 is categorized as an XML External Entity (XXE) vulnerability affecting LogicalDoc.
4
What versions of LogicalDoc are affected by CVE-2017-1000021?
Versions of LogicalDoc Community Edition up to and including 7.5.3 are affected by CVE-2017-1000021.
5
What are the potential impacts of CVE-2017-1000021?
Exploitation of CVE-2017-1000021 can lead to unauthorized access to sensitive files on the server.