CVE-2023-32635

Publication date

2023-07-19 05:54:29

Family

jpcert

State

PUBLISHED

Description

XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.