16.5.0
11 years ago
25 days ago
Known vulnerabilities in the net.sf.mpxj:mpxj package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
net.sf.mpxj:mpxj is a Library that provides facilities to allow project information to be manipulated in Java and .Net. Affected versions of this package are vulnerable to Directory Traversal via the file reading process for PRX or STX files. An attacker can cause files to be written to arbitrary locations on the file system by supplying a specially crafted file. How to fix Directory Traversal? Upgrade | [7.3.0,16.5.0) |
net.sf.mpxj:mpxj is a Library that provides facilities to allow project information to be manipulated in Java and .Net. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection in the How to fix XML External Entity (XXE) Injection? Upgrade | [5.5.5,16.4.1) |