CVE-2024-9044CWE-611CWE-827

XML External Entity (XXE) Vulnerability in EasyTax

Medium · published November 29, 2024

CVSS v4.0
4.6
EPSS
0%
Percentile
9.8
In the wild
Unconfirmed
What it is

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

The record
Technical detail
CVSS v4.0
4.6 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:N/SA:L
EPSS
0.00200 · 9.8th percentile
Weaknesses
CWE-611 · Improper Restriction of XML External Entity Reference; CWE-827 · Improper Control of Document Type Definition
Published
2024-11-29T07:40Z
EPSS history
Timeline
  • 29 NOV 07:40Z
    XML External Entity (XXE) Vulnerability in EasyTax
    cvelistv5