PT-2026-97035 · Mpxj · Mpxj
CVE-2026-61570
·
Published
2026-09-22
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MPXJ versions 5.5.5 through 16.4.0
Description
When parsing XML from the
ZTIMEINTERVALS column of a Merlin project SQLite database, the software creates a DocumentBuilder with default settings that leave doctype declarations and external entities enabled. This allows a crafted database to trigger the parser to read an arbitrary local file, although the subsequent processing of the parsed XML makes the disclosure of the file contents unlikely.Recommendations
Update to version 16.4.1.
Avoid reading Merlin project files.
Only accept Merlin project files from trusted sources.
Preprocess Merlin SQLite databases to strip doctype declarations from the
ZTIMEINTERVALS column.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mpxj