HIGH
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration
Published Dec 27, 2018
8.8
HIGHCVSS 3.0
EPSS 1.47%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.