CVE-2023-49234

MEDIUM

Stilog Visual Planning 8 - Authenticated XML External Entity Injection

Title source: llm
STIX 2.1

Description

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

Scores

CVSS v3 6.3
EPSS 0.0023
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Published Mar 29, 2024
Tracked Since Feb 18, 2026