Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Agiloft XML external entity local path traversal
Vulnerability Description
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Vulnerability Title
Agiloft 安全漏洞
Vulnerability Description
Agiloft是美国Agiloft公司的一个合同管理平台。 Agiloft存在安全漏洞,该漏洞源于XML外部实体注入,可能导致路径遍历。
CVSS Information
N/A
Vulnerability Type
N/A