Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30411
HistoryMay 10, 2021 - 3:06 p.m.

XML External Entity (XXE)

2021-05-1015:06:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
svglib
xml external entity
input sanitization
vulnerability

EPSS

0.003

Percentile

68.2%

svglib is vulnerable to XML External Entity attacks. The vulnerability exists due to svglib not sanitizing the XML input containing reference to external entity by the XML parser.

EPSS

0.003

Percentile

68.2%