Description
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
Scores
CVSS v4
4.6
EPSS
0.0006
EPSS Percentile
16.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
CWE-827
Status
published
Products (3)
msg Suisse AG/EasyTax
2022 - 1.3
msg Suisse AG/EasyTax
2023 - 1.2
msg Suisse AG/EasyTax
<= 2021
Published
Nov 29, 2024
Tracked Since
Feb 18, 2026