#VU14515 XXE attack in dom4j - CVE-2018-1000632
Published: August 21, 2018 / Updated: August 23, 2018
dom4j
dom4j
Description
The vulnerability allows a remote attacker to conduct XXE attack on the target system.
The vulnerability exists due to improper sanitization of elements and attribute names in XML documents. A remote attacker can trick the victim into opening a specially crafted XML document that submits malicious input, perform XXE attack and bypass security restrictions to access and modify sensitive information on the system.