CVE-2024-39334

MEDIUM

MENDELSON AS4 <2024 B376 - Code Injection

Title source: llm
STIX 2.1

Description

MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the details of this transaction in the client, files can be written to the computer on which the client process is running. (The server process is not affected.)

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0036
EPSS Percentile 27.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-502
Status published
Published Jun 23, 2024
Tracked Since Feb 18, 2026