iText PDF Library 7.0.2 / 5.5.11 / 2.0.8 XXE Injection

Discussion in 'News Aggregator' started by Packet Storm, 8 Nov 2017.

  1. Packet Storm

    Packet Storm Guest

    iText PDF Library versions 2.0.8, 5.5.11, and 7.0.2 suffer from an XML external entity injection vulnerability. The attack can be carried out by submitting a malicious PDF to an iText application that parses XML data. By providing a malicious XXE payloads inside the XML data that resides in the PDF, an attacker can for example extract files or forge requests on the server.

    Continue reading...
     

Share This Page

Loading...