Security Advisory

CVE-2022-1018

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-01 22:17:24
Last updated 2025-04-16 16:32:28
Assigner icscert
CVSS score 5.5
State PUBLISHED

Description

When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.