Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqvm-6hhw-247j

Опубликовано: 05 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

XML Injection vulnerability in xmltodict allows Input Data Manipulation.This issue affects xmltodict: 0.14.2.

XML Injection vulnerability in xmltodict allows Input Data Manipulation.This issue affects xmltodict: 0.14.2.

EPSS

Процентиль: 37%
0.00447
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-91

Связанные уязвимости

ubuntu
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

CVSS3: 5.3
redhat
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

nvd
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

debian
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulatio ...

suse-cvrf
10 месяцев назад

Security update for python-xmltodict

EPSS

Процентиль: 37%
0.00447
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-91