cbcvebase.
CVE-2020-25020
published 2020-08-29

CVE-2020-25020: MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

Affected

7 ranges
VendorProductVersion rangeFixed in
mpxjmpxj<= 8.1.3
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier17.7 – 17.12
CVE-2020-25020 — XML External Entity (XXE) Injection | cvebase