Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-12415
HistoryOct 23, 2019 - 8:15 p.m.

Xxe

2019-10-2320:15:00
PRIOn knowledge base
www.prio-n.com
12

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.7%

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

References

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

40.7%