Vulnerabilities > CVE-2023-27527 - XXE vulnerability in Touki-Kyoutaku-Online Shinseiyo Sogo Soft 7.9A

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
touki-kyoutaku-online
CWE-611

Summary

Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.