XXE Vulnerability in ConeXware PowerArchiver

XXE Vulnerability in ConeXware PowerArchiver

CVE-2021-28684 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).

Learn more about our External Network Penetration Testing.