ZDI-CAN-18905: ZDI-23-1037: VBASE VISAM Automation Base VBASE-Editor WebRemote File Parsing XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of VBASE VISAM Automation Base. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18905?
The severity of ZDI-CAN-18905 is classified as critical due to the potential for remote information disclosure.
How do I fix ZDI-CAN-18905?
To fix ZDI-CAN-18905, ensure that all installations of VBASE VISAM Automation Base are updated to the latest patched version from the vendor.
What type of attack vector does ZDI-CAN-18905 use?
ZDI-CAN-18905 is exploited through social engineering, requiring user interaction to visit a malicious page or open a malicious file.
What can attackers gain from exploiting ZDI-CAN-18905?
Attackers exploiting ZDI-CAN-18905 can disclose sensitive information from affected installations.
Is user interaction necessary for ZDI-CAN-18905 exploitation?
Yes, user interaction is necessary for exploiting ZDI-CAN-18905 as the target must open a malicious file or visit a malicious page.