vendor:
Easy XML Editor
by:
Javier Olmedo
8.8
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: Easy XML Editor
Affected Version From: 1.7.8 and before
Affected Version To: 1.7.8 and before
Patch Exists: NO
Related CWE: 2019-19031
CPE: edit-xml.com/Easy_XML_Editor.exe
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro
2018
Easy XML Editor 1.7.8 – XML External Entity Injection
Easy XML Editor version 1.7.8 and before are affected by XML External Entity Injection vulnerability through the malicious XML file. This allows a malicious user to read arbitrary files.
Mitigation:
Update to the latest version of Easy XML Editor