XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Link | Tags |
---|---|
https://www.inetsoftware.de/documentation/clear-reports/release-notes/releases | release notes vendor advisory |
https://www.inetsoftware.de/documentation/clear-reports/release-notes/releases/changes_20.4 | release notes vendor advisory |