CVE-2024-9044

MEDIUM

Easy Tax Client Software <2023.1.2 - XSS

Title source: llm
STIX 2.1

Description

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

Scores

CVSS v4 4.6
EPSS 0.0006
EPSS Percentile 16.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611 CWE-827
Status published
Products (3)
msg Suisse AG/EasyTax 2022 - 1.3
msg Suisse AG/EasyTax 2023 - 1.2
msg Suisse AG/EasyTax <= 2021
Published Nov 29, 2024
Tracked Since Feb 18, 2026