Description
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
References (1)
Core 1
Core References
Scores
CVSS v4
4.6
EPSS
0.0019
EPSS Percentile
9.2%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
CWE-827
Status
published
Products (3)
msg Suisse AG/EasyTax
2022 - 1.3
msg Suisse AG/EasyTax
2023 - 1.2
msg Suisse AG/EasyTax
<= 2021
Published
Nov 29, 2024
Tracked Since
Feb 18, 2026