HuTool XML parsing module has blind XXE vulnerability
High severity
GitHub Reviewed
Published
Jun 15, 2023
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Description
Published by the National Vulnerability Database
Jun 15, 2023
Published to the GitHub Advisory Database
Jun 15, 2023
Reviewed
Jun 16, 2023
Last updated
Mar 1, 2024
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax of the file XmlUtil.java of the component XML Parsing Module. The manipulation leads to xml external entity reference.
References