CVE Database
/

CVE-2019-12415

Back to search

CVE-2019-12415

Published: Oct 23, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

VendorProductVersions

n/a

Apache POI

affected
Apache POI up to 4.1.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now