CVE-2023-1288: ENOVIA Live Collaboration V6R2013xE is affected by an XML External Entity injection (XXE) vulnerability
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this XXE vulnerability?
The vulnerability ID for this XML External Entity injection (XXE) vulnerability is CVE-2023-1288.
What is the severity of CVE-2023-1288?
The severity of CVE-2023-1288 is high with a CVSS score of 7.5.
How does the XXE vulnerability in ENOVIA Live Collaboration V6R2013xE work?
The XXE vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server by injecting malicious XML entities.
Is there a fix available for CVE-2023-1288?
Yes, it is recommended to apply the latest security patch provided by 3DS to fix the XXE vulnerability in ENOVIA Live Collaboration V6R2013xE.
Where can I find more information about CVE-2023-1288?
You can find more information about CVE-2023-1288 in the vulnerability advisories provided by 3DS at the following link: https://www.3ds.com/vulnerability/advisories