CVE-2024-9044CWE-611CWE-827
XML External Entity (XXE) Vulnerability in EasyTax
Medium · published November 29, 2024
What it is
A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.
The record
Technical detail
- CVSS v4.0
- 4.6 · MEDIUM
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L
- EPSS
- 0.00200 · 9.8th percentile
- Weaknesses
- CWE-611 · Improper Restriction of XML External Entity Reference; CWE-827 · Improper Control of Document Type Definition
- Published
- 2024-11-29T07:40Z
EPSS history
Timeline