XXE (XML External Entity) Vulnerability in NSA Ghidra 9.0.1 and earlier

XXE (XML External Entity) Vulnerability in NSA Ghidra 9.0.1 and earlier

CVE-2019-13625 · HIGH Severity

AV:N/AC:L/AU:N/C:N/I:C/A:C

NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.

Learn more about our Web Application Penetration Testing UK.