Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9375

Опубликовано: 01 сент. 2025
Источник: debian
EPSS Низкий

Описание

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-xmltodictunfixedpackage
python-xmltodictno-dsatrixiepackage
python-xmltodictno-dsabookwormpackage

Примечания

  • https://github.com/martinblech/xmltodict/issues/377

  • https://fluidattacks.com/advisories/mono

  • https://github.com/martinblech/xmltodict/commit/ecd456ab88d379514b116ef9293318b74e5ed3ee (v0.15.0)

  • https://github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33 (v0.15.1)

EPSS

Процентиль: 23%
0.00074
Низкий

Связанные уязвимости

ubuntu
16 дней назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.

CVSS3: 5.3
redhat
16 дней назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.

nvd
16 дней назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.

github
13 дней назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation.This issue affects xmltodict: 0.14.2.

EPSS

Процентиль: 23%
0.00074
Низкий