← Back

CVE-2024-31573

nvd nist
Published: Oct 17, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
4.0
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.4 / Impact: 2.5
Source: MITRE (Secondary)

Description

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

Timeline

No history available yet.