Unrated severityNVD Advisory· Published May 13, 2025· Updated May 13, 2025
CVE-2024-51445
CVE-2024-51445
Description
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to read arbitrary data from the application server.
Affected products
3V2310 all versions, V2404 < V2404.4+ 2 more
- (no CPE)range: V2310 all versions, V2404 < V2404.4
- (no CPE)range: 0
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.