modery/PowerDocu

modery/PowerDocu

Releases30
Frequency1 month 3 weeks
Last Release
Stars623
Generate technical documentation from your existing Power Platform solutions, including Flows, apps, agents, Dataverse tables, and more

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files, allowing an attacker to instantiate arbitrary .NET objects and execute code. This vulnerability is fixed in 2.4.0.