CVE-2016-5000

MEDIUM

Apache Poi < 3.13 - XXE

Title source: rule

Description

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Scores

CVSS v3 5.5
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-611
Status draft

Affected Products (2)

apache/poi < 3.13
org.apache.poi/poi-examples < 3.14Maven

Timeline

Published Aug 05, 2016
Tracked Since Feb 18, 2026