ZDI-CAN-18877: ZDI-23-1038: VBASE VISAM Automation Base VBASE-Editor ProjektInfo File Parsing XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of VBASE VISAM Automation Base. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18877?
ZDI-CAN-18877 is considered a moderate severity vulnerability due to the requirement for user interaction to exploit it.
How do I fix ZDI-CAN-18877?
To fix ZDI-CAN-18877, ensure that you apply the latest security patches provided by VBASE for the VISAM Automation Base.
What kind of attack is possible with ZDI-CAN-18877?
ZDI-CAN-18877 allows remote attackers to disclose sensitive information through user interaction with malicious pages or files.
What software is affected by ZDI-CAN-18877?
ZDI-CAN-18877 affects installations of VBASE VISAM Automation Base.
Is user interaction required to exploit ZDI-CAN-18877?
Yes, user interaction is required to exploit ZDI-CAN-18877, as the target must visit a malicious page or open a malicious file.