Vulnerability Description
An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opencrx | Opencrx | 5.2.2 |
Related Weaknesses (CWE)
References
- https://gist.github.com/spookhorror/9519fc66d3946e887e4a86c06ddbee0eThird Party Advisory
- https://github.com/opencrx/opencrx/commit/ce7a71db0bb34ecbcb0e822d40598e410a48b3Patch
- https://gist.github.com/spookhorror/9519fc66d3946e887e4a86c06ddbee0eThird Party Advisory
- https://github.com/opencrx/opencrx/commit/ce7a71db0bb34ecbcb0e822d40598e410a48b3Patch
FAQ
What is CVE-2023-46502?
CVE-2023-46502 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.
How severe is CVE-2023-46502?
CVE-2023-46502 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-46502?
Check the references section above for vendor advisories and patch information. Affected products include: Opencrx Opencrx.