First published: Mon Dec 10 2018(Updated: )
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accusoft PrizmDoc | <13.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15805 is considered a high severity vulnerability due to its potential for unauthorized file access and denial of service.
To fix CVE-2018-15805, upgrade to Accusoft PrizmDoc version 13.5 or later.
CVE-2018-15805 is classified as an XML External Entity (XXE) vulnerability.
An attacker can read arbitrary files or cause a denial of service using CVE-2018-15805.
CVE-2018-15805 affects all versions of Accusoft PrizmDoc prior to 13.5.