16.6.0
5 years ago
18 hours ago
Known vulnerabilities in the mpxj package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
mpxj is a Python wrapper for the MPXJ Java library for manipulating project files Affected versions of this package are vulnerable to Directory Traversal via the file reading process for PRX or STX files. An attacker can cause files to be written to arbitrary locations on the file system by supplying a specially crafted file. How to fix Directory Traversal? Upgrade | [,16.5.0) |
mpxj is a Python wrapper for the MPXJ Java library for manipulating project files Affected versions of this package are vulnerable to XML External Entity (XXE) Injection in the How to fix XML External Entity (XXE) Injection? Upgrade | [,16.4.1) |