Vulnerabilities > CVE-2024-21796 - XXE vulnerability in Dfeg Electronic Deliverables Creation Support Tool
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |