CVE-2024-51135: Powertac-Server
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
Affected products
- Powertac-Server Powertac-Server: version 1.9.0 only
Published 2024-11-11. Last modified 2026-06-17.