CVE-2024-21765: Cals-Ed Electronic Delivery Check System

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

Affected products

  • Cals-Ed Electronic Delivery Check System: before 11.0.0 (fixed in 11.0.0); before 13.0.0 (fixed in 13.0.0); before 19.0.0 (fixed in 19.0.0)
  • Cals-Ed Electronic Delivery Item Inspection Support System: up to and including 4.0.31

Published 2024-01-24. Last modified 2026-06-17.