Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xx4-xq65-r6v3

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.9

Описание

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

EPSS

Процентиль: 18%
0.00262
Низкий

2.9 Low

CVSS4

Дефекты

CWE-91

Связанные уязвимости

ubuntu
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

CVSS3: 5.3
redhat
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

nvd
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

msrc
4 дня назад

XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization

debian
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, ...

EPSS

Процентиль: 18%
0.00262
Низкий

2.9 Low

CVSS4

Дефекты

CWE-91