CVE detail
CVE-2020-12684 — CVE-2020-12684
Published 2020-07-15 · Modified 2026-06-17 · Vendor inetsoftware · Product i-net_clear_reports · Source nvd
CRITICAL
severity
CVSS-derived band
0.0112
EPSS probability
exploitation probability, 30d
63.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References