CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in tempo...Show more |
2Mpxj Oracle2Mpxj Primavera UnifierMay 5, 2025 Dec 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations. |
2Mpxj Oracle2Mpxj Primavera UnifierMay 5, 2025 Aug 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. |