5.3
CVSSv3

CVE-2023-26559

Published: 14/04/2023 Updated: 22/04/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A directory traversal vulnerability in Oxygen XML Web Author prior to 25.0.0.3 build 2023021715 and Oxygen Content Fusion prior to 5.0.3 build 2023022015 allows an malicious user to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sync oxygen content fusion

sync oxygen xml web author