VYPR
Critical severity9.8NVD Advisory· Published Aug 29, 2020· Updated Jun 17, 2026

CVE-2020-25020

CVE-2020-25020

Description

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
net.sf.mpxj:mpxjMaven
< 8.1.48.1.4

Affected products

9
  • cpe:2.3:a:mpxj:mpxj:*:*:*:*:*:*:*:*
    Range: <=8.1.3
  • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.7,<=17.12
    • cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
  • MPXJ/MPXJdescription
  • ghsa-coords
    Range: < 8.1.4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.