CVE-2022-1704
05.08.2022, 16:15
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.Enginsight
Vendor | Product | Version |
---|---|---|
inductiveautomation | ignition | 7.9.0 ≤ 𝑥 < 7.9.21 |
inductiveautomation | ignition | 8.1.0 ≤ 𝑥 < 8.1.8 |
𝑥
= Vulnerable software versions