Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

xxe vulnerability in ebookmeta.get_metadata() #16

Open
peri0d opened this issue May 26, 2024 · 0 comments
Open

xxe vulnerability in ebookmeta.get_metadata() #16

peri0d opened this issue May 26, 2024 · 0 comments

Comments

@peri0d
Copy link

peri0d commented May 26, 2024

I found that when the ebookmeta version is less than 1.2.8 and the lxml version is less than 4.9.1, the ebookmeta.get_metadata function will have an xxe vulnerability. An attacker could use this vulnerability to read sensitive information from the server.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant