tsClinical-OSS-Community/tsc-desktop

tsClinical-OSS-Community/tsc-desktop

Releases6
Frequency11 months 1 day
Last Release
Stars9
tsClinical Metadata Desktop Tools

CVE History

CVEPublishedCVSS v3CVSS v2
7.4 HIGH

Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file.