CVE-2023-2806: Weaver e-cology API RequestInfoByXml xml external entity reference
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2806?
CVE-2023-2806 is classified as problematic due to its potential to allow XML external entity reference attacks.
How do I fix CVE-2023-2806?
To fix CVE-2023-2806, ensure that you update Weaver e-cology to a version later than 9.0 which addresses this vulnerability.
What component is affected by CVE-2023-2806?
CVE-2023-2806 affects the RequestInfoByXml function of the Weaver e-cology API.
What is the impact of CVE-2023-2806?
The impact of CVE-2023-2806 can lead to unauthorized access to sensitive data through XML external entity reference.
Which version of Weaver e-cology is vulnerable to CVE-2023-2806?
Version 9.0 of Weaver e-cology is the affected version vulnerable to CVE-2023-2806.