CVE-2023-46502
maven/org.opencrx/opencrx-core
Improper Restriction of XML External Entity Reference
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
Version 5.2.2
Upgrade to version 5.3.0 or above.
2023-11-07
source |