XML External Entity (XXE) Injection
Affecting jstoxml package, versions <2.0.0
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
jstoxml is a Converts JavaScript/JSON to XML (for RSS, Podcasts, AMP, etc.)
Affected versions of this package are vulnerable to XML External Entity (XXE) Injection due to not escaping special characters.
Remediation
Upgrade jstoxml
to version 2.0.0 or higher.
References
CVSS Score
7.3
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- Credit
- wetneb
- CWE
- CWE-611
- Snyk ID
- SNYK-JS-JSTOXML-1017039
- Disclosed
- 11 Oct, 2020
- Published
- 26 Oct, 2020