First published: Mon Dec 23 2024(Updated: )
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Credit: cve@mitre.org
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.