CVE-2019-13358

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
5
MEDIUM
Affected
1
PROJECT

Description

lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.

Open-source applicant tracking system (ATS) and recruitment CRM for staffing agencies and hiring teams.
GitHubGitHub
695