Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.
2025-08-26T23:15:35.033
2025-09-02T17:59:05.770
Analyzed
9119a7d8-5eab-497f-8521-727c672e3725
CVSSv3.1: 4.1 (MEDIUM)