{"id":"GHSA-2g98-f9jv-w8c5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2g98-f9jv-w8c5","summary":"robrichards/xmlseclibs XPath injection","details":"A vulnerability has been identified in the robrichards/xmlseclibs library, specifically related to XPath injection. The issue arises from inadequate filtering of user input before it is incorporated into XPath expressions.","published":"2024-05-20T18:06:52Z","modified":"2024-12-05T05:40:08.868202Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"robrichards/xmlseclibs","fixedVersion":"3.0.2"}],"fix":{"url":"https://github.com/robrichards/xmlseclibs/commit/649032643f7aac493e91ca318da0339aec72aa4a","label":"robrichards/xmlseclibs@6490326"},"references":[{"type":"WEB","url":"https://github.com/robrichards/xmlseclibs/commit/649032643f7aac493e91ca318da0339aec72aa4a"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/robrichards/xmlseclibs/2018-09-27.yaml"},{"type":"PACKAGE","url":"https://github.com/robrichards/xmlseclibs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:40:08.868202Z"}}