net.sf.mpxj:mpxj@16.2.0

  • latest version

    16.5.0

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    25 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the net.sf.mpxj:mpxj package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Directory Traversal

    net.sf.mpxj:mpxj is a Library that provides facilities to allow project information to be manipulated in Java and .Net.

    Affected versions of this package are vulnerable to Directory Traversal via the file reading process for PRX or STX files. An attacker can cause files to be written to arbitrary locations on the file system by supplying a specially crafted file.

    How to fix Directory Traversal?

    Upgrade net.sf.mpxj:mpxj to version 16.5.0 or higher.

    [7.3.0,16.5.0)
    • H
    XML External Entity (XXE) Injection

    net.sf.mpxj:mpxj is a Library that provides facilities to allow project information to be manipulated in Java and .Net.

    Affected versions of this package are vulnerable to XML External Entity (XXE) Injection in the DocumentBuilder process when parsing XML content from the ZTIMEINTERVALS column of a Merlin project SQLite file. An attacker can access arbitrary files by supplying a specially crafted XML payload containing malicious doctype declarations.

    How to fix XML External Entity (XXE) Injection?

    Upgrade net.sf.mpxj:mpxj to version 16.4.1 or higher.

    [5.5.5,16.4.1)