CVE-2020-25020

CRITICAL

mpxj < 8.1.3 - XML External Entity Injection in GanttProjectReader and PhoenixReader

Title source: llm
STIX 2.1

Description

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

References (2)

Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html

Scores

CVSS v3 9.8
EPSS 0.0259
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-611
Status published
Products (8)
mpxj/mpxj < 8.1.3
net.sf.mpxj/mpxj 0 - 8.1.4Maven
oracle/primavera_unifier 16.1
oracle/primavera_unifier 16.2
oracle/primavera_unifier 18.8
oracle/primavera_unifier 19.12
oracle/primavera_unifier 20.12
oracle/primavera_unifier 17.7 - 17.12
Published Aug 29, 2020
Tracked Since Feb 18, 2026