Headline
GHSA-vv6q-6hwp-vrgp: easy-parse XML External Entity Injection vulnerability
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
easy-parse XML External Entity Injection vulnerability
Moderate severity GitHub Reviewed Published Jun 29, 2023 to the GitHub Advisory Database • Updated Jun 30, 2023
Related news
CVE-2020-26710: XML External Entity (XXE) · Issue #3 · uncmath25/easy-parse
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.