CVE-2023-3276

MEDIUM

Dromara hutool < 5.8.19 - XML External Entity Injection in XmlUtil.readBySax

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference. The exploit has been disclosed to the public and may be used. VDB-231626 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.231626
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.231626

Scores

CVSS v3 5.5
EPSS 0.0073
EPSS Percentile 49.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
cn.hutool/hutool-core 0Maven
dromara/hutool < 5.8.19
Published Jun 15, 2023
Tracked Since Feb 18, 2026