Vulnerability Description
OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/jcthiele/OpenXRechnungToolbox/commit/6c50e8979924b09f336c976c
- https://invoice.secvuln.info
FAQ
What is CVE-2024-58335?
CVE-2024-58335 is a vulnerability with a CVSS score of 5.0 (MEDIUM). OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/VisualizerImpl.java.
How severe is CVE-2024-58335?
CVE-2024-58335 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58335?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.