Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LatexDraw 安全漏洞
Vulnerability Description
LatexDraw是一款矢量图片编辑器。 LatexDraw 4.0及之前版本中的SVG解析功能存在XML外部实体注入漏洞。攻击者可借助特制的SVG文件利用该漏洞泄露数据,伪造服务器端请求,扫描端口或造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A