Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreePlane mindmap加载程序XML解析器安全漏洞
Vulnerability Description
FreePlane是一套免费的开源思维导图制作工具。mindmap loader是其中的一个思维导图加载程序。XML Parser是其中的一个XML文件解析器。 FreePlane 1.5.9及之前的版本中的mindmap加载程序的XML解析器存在XML外部实体注入漏洞。攻击者可通过诱使用户打开特制的思维导图文件利用该漏洞获取数据。
CVSS Information
N/A
Vulnerability Type
N/A