robrichards/xmlseclibs XPath injection
High severity
GitHub Reviewed
Published
May 20, 2024
to the GitHub Advisory Database
•
Updated May 20, 2024
Package
Affected versions
>= 1.0.0, < 3.0.2
Patched versions
3.0.2
Description
Published to the GitHub Advisory Database
May 20, 2024
Reviewed
May 20, 2024
Last updated
May 20, 2024
A vulnerability has been identified in the robrichards/xmlseclibs library, specifically related to XPath injection. The issue arises from inadequate filtering of user input before it is incorporated into XPath expressions.
References