CVE-2024-45745

TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix: TBS-6721).
Configurations

Configuration 1 (hide)

cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:*

History

22 Sep 2025, 17:17

Type Values Removed Values Added
First Time Topquadrant topbraid Edg
Topquadrant
CPE cpe:2.3:a:topquadrant:topbraid_edg:*:*:*:*:*:*:*:*
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2024/va-24-254-02.json - Third Party Advisory
References () https://www.topquadrant.com/wp-content/uploads/2024/06/changelog-8.0.1.txt - () https://www.topquadrant.com/wp-content/uploads/2024/06/changelog-8.0.1.txt - Release Notes

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) TopQuadrant TopBraid EDG anterior a la versión 8.0.1 permite que un atacante autenticado cargue un archivo DTD XML y ejecute JavaScript para leer archivos locales o acceder a URL (XXE). Corregido en la versión 8.0.1 (corrección de error: TBS-6721).

27 Sep 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.0

27 Sep 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 16:15

Updated : 2025-09-22 17:17


NVD link : CVE-2024-45745

Mitre link : CVE-2024-45745

CVE.ORG link : CVE-2024-45745


JSON object : View

Products Affected

topquadrant

  • topbraid_edg
CWE
CWE-611

Improper Restriction of XML External Entity Reference