Skip to main content

XML Injection (aka Blind XPath Injection)


Severity High
Score 7.5/10


** DISPUTED ** An issue in dom4.j v.2.1.4 and before allows a remote attacker to obtain sensitive information via the setFeature function. NOTE: the vendor and original reporter indicate that this is not a vulnerability because setFeature only sets features, which "can be safe in one case and unsafe in another."

  • LOW
  • NONE
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-91 - XML Injection (aka Blind XPath Injection)

The software does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Advisory Timeline

  • Published