ZDI-CAN-21305: Adobe RoboHelp Server UpdateCommandStream XML External Entity Processing Information Disclosure Vulnerability
CVE-2023-22274
7.5HIGH
What is CVE-2023-22274?
Adobe RoboHelp Server versions 11.4 and earlier are susceptible to an Improper Restriction of XML External Entity Reference (XXE) vulnerability. This issue allows unauthenticated attackers to exploit the system, potentially leading to sensitive information disclosure. The vulnerability can be exploited without requiring any user interaction, making it a significant risk for organizations using these affected versions.
Affected Version(s)
RoboHelp 0