XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
References
Link | Resource |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00659.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-11-11 08:15
Updated : 2023-02-07 09:15
NVD link : CVE-2022-27233
Mitre link : CVE-2022-27233
JSON object : View
CWE
CWE-91
XML Injection (aka Blind XPath Injection)
Products Affected
intel
- quartus_prime