CVE-2023-26559

MEDIUM

Oxygen XML Web Author <25.0.0.3 - Path Traversal

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0101
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
sync/oxygen_content_fusion < 5.0.3
sync/oxygen_xml_web_author < 23.1.1.4
Published Apr 14, 2023
Tracked Since Feb 18, 2026