CVE-2023-22377: XEE
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22377?
CVE-2023-22377 is an improper restriction of XML external entity reference (XXE) vulnerability that exists in tsClinical Define.xml Generator and tsClinical Metadata Desktop Tools.
What is the severity of CVE-2023-22377?
The severity of CVE-2023-22377 is high, with a CVSS score of 7.4.
Which software versions are affected by CVE-2023-22377?
CVE-2023-22377 affects tsClinical Define.xml Generator versions 1.0.0 to 1.4.0 and tsClinical Metadata Desktop Tools versions 1.0.3 to 1.1.0.
How can an attacker exploit CVE-2023-22377?
An attacker can exploit CVE-2023-22377 to obtain an arbitrary file by exploiting the improper restriction of XML external entity reference vulnerability.
Are there any references for CVE-2023-22377?
Yes, you can find more information about CVE-2023-22377 at the following references: [Link 1](https://github.com/tsClinical/tsc-desktop/security/advisories), [Link 2](https://jvn.jp/en/jp/JVN00712821/).