Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32512
HistoryOct 18, 2021 - 5:55 a.m.

XML External Entity (XXE) Injection

2021-10-1805:55:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
xxe injection
xml
stanford-corenlp

EPSS

0.004

Percentile

72.7%

stanford-corenlp is vulnerable to XML external entity (XXE) injection attacks. The vulnerability exists because the readDocument() function in ‘DomReader.java’ doesn’t disable access to external entities by default, allowing a malicious attacker to provide a crafted XML file and expose contents of local files to the remote server.

EPSS

0.004

Percentile

72.7%