XML Parsing Vulnerability in Panasonic FPWIN Pro Software
CVE-2021-32972
5.5MEDIUM
What is CVE-2021-32972?
The Panasonic FPWIN Pro software is susceptible to an XML parsing vulnerability that allows attackers to craft malicious project files. When a user executes these files, the XML parser is tricked into accessing a specified URI, leading to the embedding of potentially sensitive external content. This could result in unauthorized information disclosure, leveraging the context of the user's execution environment. Users of FPWIN Pro versions 7.5.1.1 and earlier are urged to evaluate the impact and mitigate risks associated with this vulnerability.
Affected Version(s)
Panasonic FPWIN Pro All Versions 7.5.1.1 and prior
