XML Processing Error in Syncfusion Essential Studio for ASP.NET MVC
CVE-2024-55969

9.1High

Key Information:

Vendor

Syncfusion

Vendor
CVE Published:
15 December 2024

What is CVE-2024-55969?

CVE-2024-55969 affects Syncfusion Essential Studio for ASP.NET MVC versions before 27.1.55, specifically impacting the DocIO component. The vulnerability arises when resaving a DOCX document that contains external reference XML, which results in an XMLException. This flaw can lead to unexpected behavior and potential security risks during document processing, emphasizing the necessity for users to update to version 27.1.55 or later to mitigate this issue.

References

CVSS V3.1

Score:
9.1
Severity:
High
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.