First published: Sat Aug 29 2020(Updated: )
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MPXJ | <=8.1.3 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =20.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25020.
The severity of CVE-2020-25020 is critical with a CVSS score of 9.8.
The GanttProjectReader and PhoenixReader components in MPXJ up to version 8.1.3 are affected by CVE-2020-25020.
CVE-2020-25020 allows XXE attacks due to insufficient XML input validation in the affected components.
To fix CVE-2020-25020, update MPXJ to a version beyond 8.1.3 or apply the necessary patches provided by the vendor.