Description
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1.
Problem types
CWE-91 XML Injection (aka Blind XPath Injection)
Product status
0.14.2 (custom) before 0.15.1
References
fluidattacks.com/advisories/mono
github.com/martinblech/xmltodict
github.com/martinblech/xmltodict/blob/v0.15.1/CHANGELOG.md
github.com/...ommit/f98c90f071228ed73df997807298e1df4f790c33