Vulnerabilities > CVE-2023-27527 - XXE vulnerability in Touki-Kyoutaku-Online Shinseiyo Sogo Soft 7.9A
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |