XML injection in libnmap - CVE-2019-1010017
Published: July 18, 2019
libnmap
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software does not properly handle user-supplied XML files. A remote unauthenticated attacker can trick a victim to open a specially crafted XML file that submits malicious input to the targeted system, perform an XML injection attack and crash the affected application.