FD Application Apr. 2022 Edition (Version 9.01) and previous versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mhlw fd application |