CVE-2020-25020

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
29/08/2020
Last modified:
05/05/2025

Description

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mpxj:mpxj:*:*:*:*:*:*:*:* 8.1.3 (including)
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* 17.7 (including) 17.12 (including)
cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*